Vulnerabilities
Vulnerable Software
N-Able:  >> N-Central  >> 2023.7  Security Vulnerabilities
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.
CVSS Score
5.3
EPSS Score
0.004
Published
2025-03-17
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
CVSS Score
9.1
EPSS Score
0.004
Published
2024-07-01
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
CVSS Score
9.1
EPSS Score
0.019
Published
2024-07-01


Contact Us

Shodan ® - All rights reserved