Check Point Reference: | CPAI-2021-1024 |
Date Published: | 16 Feb 2022 |
Severity: | Critical |
Last Updated: | Monday 30 December, 2024 |
Source: | |
Industry Reference: | CVE-2021-37415 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Zoho Corp ManageEngine ServiceDesk Plus 11.0 11005 Zoho Corp ManageEngine ServiceDesk Plus 11.0 11006 Zoho Corp ManageEngine ServiceDesk Plus 11.0 11007 Zoho Corp ManageEngine ServiceDesk Plus 11.0 11008 Zoho Corp ManageEngine ServiceDesk Plus 11.0 11009 Zoho Corp ManageEngine ServiceDesk Plus 11.0 11010 Zoho Corp ManageEngine ServiceDesk Plus 11.0 11011 Zoho Corp ManageEngine ServiceDesk Plus 11.1 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11100 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11101 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11102 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11103 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11104 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11105 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11106 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11107 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11108 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11109 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11110 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11111 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11112 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11113 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11114 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11115 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11116 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11117 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11118 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11119 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11120 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11121 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11122 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11123 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11124 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11125 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11126 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11127 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11128 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11129 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11130 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11131 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11132 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11133 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11134 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11135 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11136 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11137 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11138 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11139 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11140 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11141 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11142 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11143 Zoho Corp ManageEngine ServiceDesk Plus 11.1 11144 Zoho Corp ManageEngine ServiceDesk Plus 11.2 Zoho Corp ManageEngine ServiceDesk Plus 11.2 11200 Zoho Corp ManageEngine ServiceDesk Plus 11.2 11201 Zoho Corp ManageEngine ServiceDesk Plus 11.2 11202 Zoho Corp ManageEngine ServiceDesk Plus 11.2 11203 Zoho Corp ManageEngine ServiceDesk Plus 11.2 11204 |
Vulnerability Description | An authentication bypass vulnerability exists in the Zoho ManageEngine ServiceDesk. Successful exploitation of this vulnerability would allow remote attackers to gain unauthorized access into the affected system. |
This protection detects attempts to exploit this vulnerability.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Web Server Enforcement Violation.
Attack Information: Zoho ManageEngine ServiceDesk Authentication Bypass (CVE-2021-37415)