Vulnerability record · CVE-2021-20081 · published 10 June 2021
CVE-2021-20081: ManageEngine ServiceDesk Plus input validation flaw enables SYSTEM command execution
Zohocorp · Manageengine Servicedesk Plus
ManageEngine ServiceDesk Plus before version 11205 fails to properly restrict disallowed inputs, allowing a remote authenticated attacker to execute arbitrary commands. Because the commands run with SYSTEM privileges, a valid low-privilege account can fully compromise the server.
Description
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 with SYSTEM-level impact and public exploit code, though exploitation requires authenticated high privileges.
What it is
ManageEngine ServiceDesk Plus before version 11205 fails to properly restrict disallowed inputs, allowing a remote authenticated attacker to execute arbitrary commands. Because the commands run with SYSTEM privileges, a valid low-privilege account can fully compromise the server.
Impact
An attacker gains arbitrary command execution as SYSTEM on the ServiceDesk Plus host, leading to full server compromise, data theft, and potential lateral movement.
Attack surface
Reachable over the network (AV:N) with no user interaction (UI:N), but it requires an authenticated account with high privileges (PR:H) per the CVSS vector.
Exploitation
Not listed in CISA KEV, but EPSS is 0.5242 (98.9th percentile) and both references are tagged Exploit, indicating public exploit code exists and exploitation is likely.
What to do
- Upgrade ManageEngine ServiceDesk Plus to version 11205 or later immediately.
- Restrict network access to the ServiceDesk Plus web interface to trusted management networks.
- Enforce least privilege and strong authentication for ServiceDesk Plus accounts, and audit privileged accounts.
- Monitor for and remove any unauthorized accounts or scheduled tasks created after exploitation.
Detection
- Search ServiceDesk Plus logs for unexpected command execution or process creation events.
- Monitor for child processes spawned by the ServiceDesk Plus service (e.g., cmd.exe, powershell.exe) on the host.
- Alert on unusual outbound network connections from the ServiceDesk Plus server.
- Review authentication logs for anomalous privileged account activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2021-22 | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2021-22 | ExploitThird Party Advisory |
Track CVE-2021-20081 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.