Impact
Zohocorp ManageEngine DDI Central versions before 6201 contain an insufficient access control flaw on the HA failover endpoint. The endpoint allows destructive PostgreSQL database operations that can delete or corrupt entire configuration data when accessed. The flaw can be abused to achieve full data loss or compromise of system integrity.
Affected Systems
The affected product is Zohocorp DDI Central, any installation with a version earlier than 6201. These releases expose the failover endpoint without proper authorization checks, allowing attackers to trigger destructive database actions.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the attack surface is likely reachable over the network. Based on the description, it is inferred that the HA failover endpoint can be accessed remotely, making the flaw exploitable by an attacker who can communicate with that endpoint. The absence of known widespread exploits does not reduce the severity of the potential impact and requires urgent action.
OpenCVE Enrichment