CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-28200

CVSS 9.1v3.1pub. 2024-07-01upd. 2024-11-21

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-287 (Improper Authentication) consists of the ability to bypass authentication mechanisms of the N-Central server user interface. An unauthenticated remote attacker can exploit an alternative path or improperly implemented identity verification process to gain access to the interface without possessing valid credentials. The vulnerability was disclosed during an internal source code review of N-Central by the N-able team.

Impact

An attacker can gain unauthorized access to the N-Central management interface, which can consequently lead to takeover of managed devices, disclosure of sensitive data, or modification of IT environment configuration.

Mitigation & patch

N-Central should be updated to version 2024.2 or newer, in accordance with information contained in the vendor's official Release Notes available at the address indicated in the references. It is also recommended to restrict network access to the N-Central management interface exclusively to trusted IP addresses.

Who is affected

All N-Able N-Central deployments in versions earlier than 2024.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • N Able N Central

    APP
    N-Able
    < 2024.2
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-8875CRITICAL9.4⚠ KEVPL ✓same product

Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE

CVE-2025-8876CRITICAL9.4⚠ KEVPL ✓same product

OS Command Injection w N-able N-central (przed wersją 2025.3.1)

CVE-2025-11367CRITICAL10.0PL ✓same product

RCE przez deserialization w N-Able N-Central Software Probe

CVE-2025-11366CRITICAL9.4PL ✓same product

Authentication bypass via path traversal w N-Able N-Central

CVE-2024-5322CRITICAL9.1PL ✓same product

Authentication Bypass w N-Able N-Central poprzez session rebinding (Entra SSO)