N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
Posts tagged: N-Able
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
An unauthenticated attacker can slip past N-central’s login checks via an alternate access path, reading and altering data on a platform many MSPs use to manage customer endpoints.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
A second, more thorough fix was needed after an earlier patch for N-central’s login flow failed to close an alternate authentication path, letting attackers seize administrator accounts outright.