Check Point Advisories

Zoho ManageEngine ServiceDesk Authentication Bypass (CVE-2021-37415)

Check Point Reference: CPAI-2021-1024
Date Published: 16 Feb 2022
Severity: Critical
Last Updated: Monday 30 December, 2024
Source:
Industry Reference:CVE-2021-37415
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Zoho Corp ManageEngine ServiceDesk Plus 11.0 11005
Zoho Corp ManageEngine ServiceDesk Plus 11.0 11006
Zoho Corp ManageEngine ServiceDesk Plus 11.0 11007
Zoho Corp ManageEngine ServiceDesk Plus 11.0 11008
Zoho Corp ManageEngine ServiceDesk Plus 11.0 11009
Zoho Corp ManageEngine ServiceDesk Plus 11.0 11010
Zoho Corp ManageEngine ServiceDesk Plus 11.0 11011
Zoho Corp ManageEngine ServiceDesk Plus 11.1
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11100
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11101
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11102
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11103
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11104
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11105
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11106
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11107
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11108
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11109
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11110
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11111
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11112
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11113
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11114
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11115
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11116
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11117
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11118
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11119
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11120
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11121
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11122
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11123
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11124
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11125
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11126
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11127
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11128
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11129
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11130
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11131
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11132
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11133
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11134
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11135
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11136
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11137
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11138
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11139
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11140
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11141
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11142
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11143
Zoho Corp ManageEngine ServiceDesk Plus 11.1 11144
Zoho Corp ManageEngine ServiceDesk Plus 11.2
Zoho Corp ManageEngine ServiceDesk Plus 11.2 11200
Zoho Corp ManageEngine ServiceDesk Plus 11.2 11201
Zoho Corp ManageEngine ServiceDesk Plus 11.2 11202
Zoho Corp ManageEngine ServiceDesk Plus 11.2 11203
Zoho Corp ManageEngine ServiceDesk Plus 11.2 11204
Vulnerability Description An authentication bypass vulnerability exists in the Zoho ManageEngine ServiceDesk. Successful exploitation of this vulnerability would allow remote attackers to gain unauthorized access into the affected system.

Protection Overview

This protection detects attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.

Security Gateway R81 / R80 / R77 / R75

  1. In the IPS tab, click Protections and find the Zoho ManageEngine ServiceDesk Authentication Bypass (CVE-2021-37415) protection using the Search tool and Edit the protection's settings.
  2. Install policy on all Security Gateways.

This protection's log will contain the following information:

Attack Name:  Web Server Enforcement Violation.
Attack Information:  Zoho ManageEngine ServiceDesk Authentication Bypass (CVE-2021-37415)

×
  Feedback
This website uses cookies for its functionality and for analytics and marketing purposes. By continuing to use this website, you agree to the use of cookies. For more information, please read our Cookies Notice.
OK