CVE-2020-28653
CRITICAL EXPLOITED NUCLEIManageEngine OpManager < 125203 - Remote Code Execution via Smart Update Manager Servlet
Title source: llmExploitation Summary
CVE-2020-28653 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 4 public exploits from researchers including tuo4n8, intrigueio, mr-r3bot, including a Metasploit module exploits/multi/http/opmanager_sumpdu_deserialization.
A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2020-28653, targeting a deserialization vulnerability in AdventNet ManageEngine products (2016-2020). The exploit sends a crafted payload to trigger remote code execution via a vulnerable servlet endpoint.
Description
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
Exploits (4)
The repository contains a functional exploit for CVE-2020-28653, targeting a deserialization vulnerability in AdventNet ManageEngine products (2016-2020). The exploit sends a crafted payload to trigger remote code execution via a vulnerable servlet endpoint.
This repository contains a functional exploit PoC for CVE-2020-28653, a deserialization vulnerability in ManageEngine OpManager. The exploit uses ysoserial to generate a malicious payload that triggers a DNS lookup upon deserialization, confirming vulnerability.
This repository contains a functional exploit for CVE-2020-28653, targeting ManageEngine OPManager. It includes a Java deserialization gadget (CommonsBeanutils1) and a Python script to deliver the payload via HTTP requests to vulnerable endpoints.
This Metasploit module exploits a Java deserialization vulnerability in ManageEngine OpManager's Smart Update Manager component, allowing unauthenticated remote code execution (RCE) as SYSTEM/root. It supports multiple payload types and targets versions 12.1 to 12.5.328.
Nuclei Templates (1)
http.title:"opmanager plus" || http.title:"opmanager"
title="opmanager plus" || title="opmanager"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H