### [CVE-2015-9107](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9107) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor. ### POC #### Reference No PoCs from references. #### Github - https://github.com/theguly/DecryptOpManager - https://github.com/theguly/exploits