Use of hard-coded credentials in ManageEngine DDI Central - CVE-2024-5471

 

Use of hard-coded credentials in ManageEngine DDI Central - CVE-2024-5471

Published: May 6, 2024 / Updated: August 15, 2026


Vulnerability identifier: #VU142618
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-5471
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized control over agent node servers.

The vulnerability exists due to use of hard-coded cryptographic keys in DDI Central Node Agent when handling agent server trust and identification. A remote attacker can leverage the hard-coded sensitive keys to gain unauthorized control over agent node servers.

The issue can compromise the security of the broader managed environment.


Affected software

ManageEngine DDI Central

How to mitigate CVE-2024-5471

Install security update from vendor's website.

ManageEngine DDI Central - update to 4002

External References

Related Security Bulletins