Impact
This vulnerability allows an authenticated user to write an arbitrary file via the HA Failover Configuration sync upload mechanism of Zohocorp ManageEngine DDI Central. By uploading a malicious configuration file, an attacker can overwrite critical files on the server, leading to remote code execution on the affected system.
Affected Systems
Zohocorp ManageEngine DDI Central versions prior to 6201 are impacted. The affected components are the HA failover configuration sync and file upload handling logic within the DDI Central application.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and although an EPSS score is not available, the vulnerability remains significant. The lack of listing in the CISA KEV catalog does not mitigate the risk. The attack requires valid administrative credentials to access the HA failover configuration sync feature, after which file write privileges lead to code execution. Given the high severity and authenticated nature, remediation is strongly urged.
OpenCVE Enrichment