Impact
An authentication bypass exists in the password‑reset workflow of ManageEngine DDI Central that allows an attacker to reset a user’s password without proper authentication, leading to full account takeover. This vulnerability is classified under CWE‑287 and CWE‑640.
Affected Systems
The flaw is present in ManageEngine DDI Central, a DNS, DHCP, and IP address management solution from Zohocorp. The CVE listing does not specify vulnerable versions or release numbers, so any installation of the product potentially is affected until an official patch is released.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, reflecting full compromise of user credentials. The EPSS score of 2% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in CISA KEV. The description indicates that an attacker can trigger the bypass by manipulating the password‑reset workflow. No further environmental constraints are described.
OpenCVE Enrichment