Zohocorp ManageEngine DDI Central 6.2.0 版本中,构建号低于 6201 的版本在高可用性(HA)配置流程中存在 Keepalived 配置注入漏洞。该漏洞允许经过身份验证的“操作员级别”用户修改 Keepalived 配置,从而可能在 DDI Central 主机上以 root 权限执行命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Zohocorp | DDI Central | 0 ~ 6201 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12268 | 8.8 HIGH | Authenticated PowerShell Injection leads to RCE |
| CVE-2026-12264 | 8.8 HIGH | Authenticated File Write via HA Failover Config Upload leads to RCE |
| CVE-2026-12265 | 8.8 HIGH | Missing Authorization on HA Failover Config allows Complete Data Destruction |
| CVE-2026-12267 | 7.2 HIGH | Authenticated PowerShell Injection in DNS Query Resolution Policy leads to RCE |
No comments yet