Vulnerabilities > CVE-2020-11532 - Insecure Default Initialization of Resource vulnerability in Zohocorp products

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
zohocorp
CWE-1188
critical

Summary

Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/157609/XL-2020-002.txt
idPACKETSTORM:157609
last seen2020-05-09
published2020-05-08
reporterSahil Dhar
sourcehttps://packetstormsecurity.com/files/157609/ManageEngine-DataSecurity-Plus-Authentication-Bypass.html
titleManageEngine DataSecurity Plus Authentication Bypass