Use of hard-coded credentials in ManageEngine DDI Central - CVE-2024-5471
Published: May 6, 2024 / Updated: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized control over agent node servers.
The vulnerability exists due to use of hard-coded cryptographic keys in DDI Central Node Agent when handling agent server trust and identification. A remote attacker can leverage the hard-coded sensitive keys to gain unauthorized control over agent node servers.
The issue can compromise the security of the broader managed environment.