CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-5322

CVSS 9.1v3.1pub. 2024-07-01upd. 2025-09-08

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.

🤖 AI Analysis
How it works

The vulnerability mechanism involves improper session handling in the login process via Entra SSO (Microsoft Entra ID). An attacker can perform so-called session rebinding — that is, bind an active, already authenticated session of another user to their own context. As a result, it is possible to take over the privileges of a logged-in user without knowing their login credentials. The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel).

Impact

A remote, unauthenticated attacker can gain unauthorized access to another user's account with full privileges, which may result in compromise of managed IT environments and unauthorized modification of configuration or data disclosure.

Mitigation & patch

N-Able N-Central should be updated to version 2024.3 or later, according to the information contained in the manufacturer's official Release Notes and security advisory. If immediate update is not possible, consider temporarily disabling Entra SSO integration.

Who is affected

All N-Able N-Central deployments with Entra SSO support enabled in versions prior to 2024.3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • N Able N Central

    APP
    N-Able
    < 2024.3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-8875CRITICAL9.4⚠ KEVPL ✓same product

Deserializacja niezaufanych danych w N-Able N-Central umożliwia RCE

CVE-2025-8876CRITICAL9.4⚠ KEVPL ✓same product

OS Command Injection w N-able N-central (przed wersją 2025.3.1)

CVE-2025-11367CRITICAL10.0PL ✓same product

RCE przez deserialization w N-Able N-Central Software Probe

CVE-2025-11366CRITICAL9.4PL ✓same product

Authentication bypass via path traversal w N-Able N-Central

CVE-2024-28200CRITICAL9.1PL ✓same product

Authentication Bypass interfejsu użytkownika w N-Able N-Central