CVE-2021-40173: CSRF

Published Aug 29, 2021
·
Updated

Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

Affected Software

17 affected components
ZohoCorp Manageengine Cloud Security Plus<=4.0
ZohoCorp Manageengine Cloud Security Plus=4.1-4100
ZohoCorp Manageengine Cloud Security Plus=4.1-4101
ZohoCorp Manageengine Cloud Security Plus=4.1-4102
ZohoCorp Manageengine Cloud Security Plus=4.1-4103
ZohoCorp Manageengine Cloud Security Plus=4.1-4104
ZohoCorp Manageengine Cloud Security Plus=4.1-4105
ZohoCorp Manageengine Cloud Security Plus=4.1-4106
ZohoCorp Manageengine Cloud Security Plus=4.1-4107
ZohoCorp Manageengine Cloud Security Plus=4.1-4108
ZohoCorp Manageengine Cloud Security Plus=4.1-4109
ZohoCorp Manageengine Cloud Security Plus=4.1-4110
ZohoCorp Manageengine Cloud Security Plus=4.1-4111
ZohoCorp Manageengine Cloud Security Plus=4.1-4112
ZohoCorp Manageengine Cloud Security Plus=4.1-4113
ZohoCorp Manageengine Cloud Security Plus=4.1-4115
ZohoCorp Manageengine Cloud Security Plus=4.1-4116

Event History

Aug 29, 2021
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-40173?

CVE-2021-40173 is a vulnerability in Zoho ManageEngine Cloud Security Plus before Build 4117 that allows a CSRF attack on the server proxy settings.

2

Which software versions are affected by CVE-2021-40173?

CVE-2021-40173 affects Zoho ManageEngine Cloud Security Plus versions 4.0 up to and including 4.1-4116.

3

What is the severity of CVE-2021-40173?

CVE-2021-40173 has a severity rating of 8.8 (high severity).

4

How can I fix CVE-2021-40173?

To fix CVE-2021-40173, you should update Zoho ManageEngine Cloud Security Plus to build 4117 or later. Make sure to check the official release notes for the update process.

5

Where can I find more information about CVE-2021-40173?

More information about CVE-2021-40173 can be found in the release notes of Zoho ManageEngine Cloud Security Plus.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203