CVE-2021-33055: OS Command Injection
Published Aug 30, 2021
·Updated
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
Affected Software
8 affected components
ZohoCorp ManageEngine ADSelfService Plus<6.1
ZohoCorp ManageEngine ADSelfService Plus=6.1
ZohoCorp ManageEngine ADSelfService Plus=6.1-6100
ZohoCorp ManageEngine ADSelfService Plus=6.1-6101
ZohoCorp ManageEngine ADSelfService Plus=6.1-6102
ZohoCorp ManageEngine ADSelfService Plus=6.1-6103
ZohoCorp ManageEngine ADSelfService Plus=6.1-6104
Microsoft Windows
Remediation
Event History
Aug 30, 2021
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
Description
Frequently Asked Questions
1
What is CVE-2021-33055?
CVE-2021-33055 is a vulnerability in Zoho ManageEngine ADSelfService Plus that allows unauthenticated remote code execution in non-English editions.
2
What is the severity level of CVE-2021-33055?
CVE-2021-33055 has a severity level of critical.
3
How does CVE-2021-33055 affect Zoho ManageEngine ADSelfService Plus?
CVE-2021-33055 allows unauthenticated remote code execution in Zoho ManageEngine ADSelfService Plus versions 6.1-6102 and below.
4
Is Microsoft Windows affected by CVE-2021-33055?
No, Microsoft Windows is not affected by CVE-2021-33055.
5
How can I fix CVE-2021-33055 in Zoho ManageEngine ADSelfService Plus?
To fix CVE-2021-33055, you should apply the latest update released by Zoho ManageEngine ADSelfService Plus.