CVE-2020-11532

CRITICAL

ManageEngine ADAudit Plus Xnode Enumeration

Title source: metasploit

Description

Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.

Exploits (2)

metasploit WORKING POC
by Sahil Dhar, Erik Wynter · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/manageengine_adaudit_plus_xnode_enum.rb
metasploit WORKING POC
by Sahil Dhar, Erik Wynter · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/manageengine_datasecurity_plus_xnode_enum.rb

Scores

CVSS v3 9.8
EPSS 0.8981
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1188
Status published
Products (2)
zohocorp/manageengine_adaudit_plus < 6.0.3
zohocorp/manageengine_datasecurity_plus < 6.0.1
Published May 08, 2020
Tracked Since Feb 18, 2026