CVE-2020-11532: Critical severity zoho manageengine adaudit plus vulnerability
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11532?
The severity of CVE-2020-11532 is critical with a severity value of 9.8.
How does CVE-2020-11532 affect Zoho ManageEngine DataSecurity Plus?
CVE-2020-11532 allows an attacker to bypass authentication for the DataEngine Xnode server in Zoho ManageEngine DataSecurity Plus.
How can an attacker exploit CVE-2020-11532?
An attacker can exploit CVE-2020-11532 by using the default admin credentials to communicate with the DataEngine Xnode server.
Is there a fix available for CVE-2020-11532?
Yes, upgrading Zoho ManageEngine DataSecurity Plus to version 6.0.1 or later will fix the vulnerability.
Where can I find more information about CVE-2020-11532?
You can find more information about CVE-2020-11532 at the provided references: [Reference 1](http://packetstormsecurity.com/files/157609/ManageEngine-DataSecurity-Plus-Authentication-Bypass.html), [Reference 2](http://seclists.org/fulldisclosure/2020/May/28), [Reference 3](https://pitstop.manageengine.com/portal/community/topic/upgrade-datasecurity-plus-to-the-build-6013-to-fix-security-issues).