Zoho ManageEngine DataSecurity Plus versions prior to 6.0.1 use hardcoded default admin credentials for communication with the DataEngine Xnode server. This allows an attacker to bypass authentication and perform any operation as the admin user on the Xnode server, effectively granting full administrative access without valid credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit auxiliary module: 'ManageEngine ADAudit Plus Xnode Enumeration'. The module targets the Xnode server component of ManageEngine ADAudit Plus, specifically versions prior to 6.0.3 (6032), exploiting default admin credentials to enumerate and dump the contents of Xnode data repositories. These repositories may contain sensitive Active Directory information such as domain names, host names, usernames, and SIDs. The module can also be used against patched versions if valid credentials are provided. It supports two main modes: dumping only specified repositories/fields (via a YAML config file) or dumping all available data (DUMP_ALL option). The module communicates with the Xnode service over TCP port 29118, and stores extracted data as loot files in JSON format. The code is written in Ruby and is structured as a standard Metasploit auxiliary module, making use of Metasploit's reporting and TCP communication libraries. No code execution or shell payload is delivered; the exploit is focused on data extraction and enumeration.
This repository contains a single Metasploit auxiliary module: 'ManageEngine DataSecurity Plus Xnode Enumeration'. The module targets the Xnode server component of ManageEngine DataSecurity Plus, specifically versions prior to 6.0.1 (6011) that are vulnerable to default admin credentials (CVE-2020-11532). The exploit connects to the Xnode service (default TCP port 29119), authenticates (using default or supplied credentials), and enumerates/dumps the contents of Xnode data repositories. These repositories may contain sensitive Active Directory information such as domain names, host names, usernames, and SIDs. The module allows for targeted dumping (using a YAML config file) or full dumping of all repositories (with the DUMP_ALL option). Extracted data is saved as JSON loot files. The code is written in Ruby and is designed to be run within the Metasploit framework. No code execution or shell payload is delivered; the exploit is focused on authenticated data extraction. The repository structure is typical for a Metasploit module, with a single Ruby file implementing all logic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.