CVE-2020-11532
CRITICALManageEngine ADAudit Plus Xnode Enumeration
Title source: metasploitDescription
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.
Exploits (2)
metasploit
WORKING POC
by Sahil Dhar, Erik Wynter · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/manageengine_adaudit_plus_xnode_enum.rb
metasploit
WORKING POC
by Sahil Dhar, Erik Wynter · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/manageengine_datasecurity_plus_xnode_enum.rb
References (3)
Scores
CVSS v3
9.8
EPSS
0.8981
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-1188
Status
published
Products (2)
zohocorp/manageengine_adaudit_plus
< 6.0.3
zohocorp/manageengine_datasecurity_plus
< 6.0.1
Published
May 08, 2020
Tracked Since
Feb 18, 2026