Description
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- N-able / N-central<2024.2 – <2024.2
Exploits & proofs of concept
- nucleiN-able N-central < 2024.2 - Authentication Bypass Detectionby rxerium
Updated 38m ago · 8 sources