VYPR

DDI Central

by Manageengine

CVEs (6)

  • CVE-2026-12571CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.03

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

  • CVE-2026-12264HigSep 28, 2026
    risk 0.57cvss 8.8epss —

    Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.

  • CVE-2026-12268HigSep 28, 2026
    risk 0.57cvss 8.8epss —

    ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.

  • CVE-2024-5471HigJul 17, 2024
    risk 0.57cvss 8.8epss 0.02

    Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

  • CVE-2026-12267HigSep 28, 2026
    risk 0.47cvss 7.2epss —

    ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.

  • CVE-2024-27311MedJul 17, 2024
    risk 0.36cvss 5.5epss 0.01

    Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.