CVE-2021-28960: Command Injection
Published Sep 21, 2021
·Updated
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.
Affected Software
1 affected component
ManageEngine Desktop Central<10.0.683
Event History
Sep 21, 2021
CVE Published
via MITRE·12:46 PM
Data Sourced
via MITRE·12:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28960?
The severity of CVE-2021-28960 is critical, with a CVSS score of 9.8.
2
How does CVE-2021-28960 affect Zoho ManageEngine Desktop Central?
CVE-2021-28960 allows unauthenticated command injection in Zoho ManageEngine Desktop Central before build 10.0.683.
3
How can I fix the CVE-2021-28960 vulnerability?
To fix the CVE-2021-28960 vulnerability, update Zoho ManageEngine Desktop Central to build 10.0.683 or later.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-28960?
The Common Weakness Enumeration (CWE) ID for CVE-2021-28960 is CWE-77.
5
Where can I find more information about CVE-2021-28960?
More information about CVE-2021-28960 can be found on the Zoho ManageEngine website.