CVE-2021-44525: Critical severity manageengine pam360 vulnerability
Published Dec 20, 2021
·Updated
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
Affected Software
23 affected components
ZohoCorp ManageEngine PAM360=4.0
ZohoCorp ManageEngine PAM360=4.0-build4001
ZohoCorp ManageEngine PAM360=4.0-build4002
ZohoCorp ManageEngine PAM360=4.1
ZohoCorp ManageEngine PAM360=4.1-build4100
ZohoCorp ManageEngine PAM360=4.1-build4101
ZohoCorp ManageEngine PAM360=4.5
ZohoCorp ManageEngine PAM360=4.5-build4500
ZohoCorp ManageEngine PAM360=4.5-build4501
ZohoCorp ManageEngine PAM360=5.0
ZohoCorp ManageEngine PAM360=5.0-build5000
ZohoCorp ManageEngine PAM360=5.0-build5001
ZohoCorp ManageEngine PAM360=5.0-build5002
ZohoCorp ManageEngine PAM360=5.0-build5003
ZohoCorp ManageEngine PAM360=5.0-build5004
ZohoCorp ManageEngine PAM360=5.1
ZohoCorp ManageEngine PAM360=5.1-build5100
ZohoCorp ManageEngine PAM360=5.2
ZohoCorp ManageEngine PAM360=5.2-build5200
ZohoCorp ManageEngine PAM360=5.3
ZohoCorp ManageEngine PAM360=5.3-build5300
ZohoCorp ManageEngine PAM360=5.3-build5301
ZohoCorp ManageEngine PAM360=5.3-build5302
Event History
Dec 20, 2021
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-44525?
The severity of CVE-2021-44525 is critical with a score of 9.8.
2
How can attackers exploit CVE-2021-44525?
Attackers can exploit CVE-2021-44525 by bypassing the authentication filter and modifying certain aspects of the application state.
3
Which versions of Zoho ManageEngine PAM360 are affected by CVE-2021-44525?
Zoho ManageEngine PAM360 versions 4.0 to 5.3 are affected by CVE-2021-44525.
4
Is authentication required to exploit CVE-2021-44525 in Zoho ManageEngine PAM360?
No, authentication is not required to exploit CVE-2021-44525 in Zoho ManageEngine PAM360.
5
How can I fix CVE-2021-44525 in Zoho ManageEngine PAM360?
To fix CVE-2021-44525 in Zoho ManageEngine PAM360, update to build 5303 or a later version.