Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-5445
Disclosure Date: August 12, 2024 (last updated January 07, 2025)
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.
0
Attacker Value
Unknown
CVE-2024-5322
Disclosure Date: July 01, 2024 (last updated July 02, 2024)
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass.
This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
0
Attacker Value
Unknown
CVE-2024-28200
Disclosure Date: July 01, 2024 (last updated August 23, 2024)
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2.
This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
0
Attacker Value
Unknown
CVE-2023-37244
Disclosure Date: May 02, 2024 (last updated May 03, 2024)
The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attacker to manipulate the process into performing arbitrary file deletions. We recommend upgrading to version 2.91.0.0
0
Attacker Value
Unknown
CVE-2023-47132
Disclosure Date: February 08, 2024 (last updated February 16, 2024)
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
0
Attacker Value
Unknown
CVE-2023-47131
Disclosure Date: February 08, 2024 (last updated February 16, 2024)
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
0
Attacker Value
Unknown
CVE-2023-27470
Disclosure Date: September 11, 2023 (last updated October 08, 2023)
BASupSrvcUpdater.exe in N-able Take Control Agent through 7.0.41.1141 before 7.0.43 has a TOCTOU Race Condition via a pseudo-symlink at %PROGRAMDATA%\GetSupportService_N-Central\PushUpdates, leading to arbitrary file deletion.
0
Attacker Value
Unknown
CVE-2023-30297
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server.
0
Attacker Value
Unknown
CVE-2007-4624
Disclosure Date: August 31, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in pframe.php in AbleDesign Dynamic Picture Frame 1.00 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-1050
Disclosure Date: February 21, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2) the keyword parameter in the search menu (go=search), or (3) the username or (4) the password in a go=Login action.
0