CVE-2021-41827: High severity ZohoCorp Manageengine Remote Access Plus vulnerability
Published Sep 30, 2021
·Updated
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
Affected Software
1 affected component
ZohoCorp Manageengine Remote Access Plus<10.1.2121.1
Event History
Sep 30, 2021
CVE Published
via MITRE·02:36 AM
Data Sourced
via MITRE·02:36 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Zoho ManageEngine Remote Access Plus vulnerability?
The vulnerability ID for this Zoho ManageEngine Remote Access Plus vulnerability is CVE-2021-41827.
2
What is the severity of CVE-2021-41827?
The severity of CVE-2021-41827 is high with a severity value of 7.5.
3
What is the description of CVE-2021-41827?
CVE-2021-41827 is a vulnerability in Zoho ManageEngine Remote Access Plus before 10.1.2121.1 that has hardcoded credentials for read-only access.
4
How does CVE-2021-41827 affect Zoho ManageEngine Remote Access Plus?
CVE-2021-41827 affects Zoho ManageEngine Remote Access Plus before version 10.1.2121.1.
5
Is there a fix for CVE-2021-41827?
Yes, there is a hotfix available that addresses CVE-2021-41827. Please refer to the hotfix readme provided by Zoho ManageEngine for more information.