CVE-2021-44515 — Zoho Desktop Central Authentication Bypass Vulnerability
CVE-2021-44515: Zoho Desktop Central Authentication Bypass Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Zoho |
| Product | Desktop Central |
| Date added | 2021-12-10 |
| Due date | 2021-12-24 |
| Ransomware campaign use | Unknown |
Description
Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-44515
Weakness behind it
CISA has not recorded a CWE for this entry, so the CVE → CWE → CAPEC → ATT&CK chain cannot be walked from here. That is a gap in the catalogue, not evidence the vulnerability has no weakness class — check the NVD record below.
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-44515
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
See all 1,745 pages under Vulnerabilities (CVE) →
Related pages
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.