CVE-2024-5322 Information

Description

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO which can lead to authentication bypass.

This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.

Reference

https://documentation.n-able.com/N-central/Release_Notes/GA/Content/2024.3%20Release%20Notes.htm https://me.n-able.com/s/security-advisory/aArVy0000000BgDKAU/cve20245322-ncentral-authentication-bypass-via-session-rebinding

Share on: