CVE-2021-37929: Malicious File Upload
Published Oct 7, 2021
·Updated
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Affected Software
6 affected components
ZohoCorp ManageEngine ADManager Plus<7.1
ZohoCorp ManageEngine ADManager Plus=7.1
ZohoCorp ManageEngine ADManager Plus=7.1-7100
ZohoCorp ManageEngine ADManager Plus=7.1-7101
ZohoCorp ManageEngine ADManager Plus=7.1-7102
ZohoCorp ManageEngine ADManager Plus=7.1-7110
Event History
Oct 7, 2021
CVE Published
via MITRE·03:22 PM
Data Sourced
via MITRE·03:22 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-37929?
The severity of CVE-2021-37929 is critical with a CVSS score of 9.8.
2
What software is affected by CVE-2021-37929?
Zoho ManageEngine ADManager Plus version 7110 and prior are affected by CVE-2021-37929.
3
What is the impact of CVE-2021-37929?
CVE-2021-37929 could allow an attacker to upload malicious files and achieve remote code execution.
4
How can I fix CVE-2021-37929?
It is recommended to upgrade to a version of Zoho ManageEngine ADManager Plus that is not affected by CVE-2021-37929.
5
Where can I find more information about CVE-2021-37929?
You can find more information about CVE-2021-37929 on the ManageEngine website and the release notes for ADManager Plus.