CVE-2021-37414: High severity ZohoCorp Manageengine Desktop Central vulnerability
Published Sep 10, 2021
·Updated
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
Affected Software
1 affected component
ZohoCorp Manageengine Desktop Central<10.0.709
Event History
Sep 10, 2021
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37414?
CVE-2021-37414 is a vulnerability in Zoho ManageEngine DesktopCentral before version 10.0.709 that allows anyone to obtain a valid user's APIKEY without authentication.
2
How severe is CVE-2021-37414?
CVE-2021-37414 has a severity rating of 7.5 (high).
3
How does CVE-2021-37414 impact Zoho ManageEngine DesktopCentral?
CVE-2021-37414 allows unauthorized individuals to obtain a valid user's APIKEY without authentication, potentially exposing sensitive data and allowing unauthorized access to the application.
4
What is the affected software for CVE-2021-37414?
The affected software is Zoho ManageEngine DesktopCentral version up to 10.0.709.
5
How can I fix CVE-2021-37414?
To fix CVE-2021-37414, update Zoho ManageEngine DesktopCentral to version 10.0.709 or later.