ZeroHour

CVE-2024-5322

CVSS 3.1
9.1 critical
EPSS
<1%p34
Published
()
Modified
Description

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.

Vendors
n-able
Products
n-central
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.