CVE-2021-41828: High severity ZohoCorp Manageengine Remote Access Plus vulnerability
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41828?
CVE-2021-41828 is a vulnerability in Zoho ManageEngine Remote Access Plus before version 10.1.2121.1 that has hardcoded credentials associated with resetPWD.xml.
How severe is CVE-2021-41828?
CVE-2021-41828 has a severity level of 7.5, which is considered high.
What software is affected by CVE-2021-41828?
Zoho ManageEngine Remote Access Plus versions up to 10.1.2121.1 are affected by CVE-2021-41828.
Is there a fix for CVE-2021-41828?
Yes, the fix for CVE-2021-41828 is available in version 10.1.2121.1 of Zoho ManageEngine Remote Access Plus.
Where can I find more information about CVE-2021-41828?
You can find more information about CVE-2021-41828 at the following references: [Medium](https://medium.com/nestedif/vulnerability-disclosure-hardcoded-keys-password-zoho-r-a-p-318aa9bba2e) and [ManageEngine](https://www.manageengine.com/remote-desktop-management/hotfix-readme.html).