CVE-2024-5445
3.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Exploitability: 1.2 / Impact: 2.5
Source: a5532a13-c4dd-4202-bef1-e0b8f2f8d12b (Secondary)
Description
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.
References (3)
Source: a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
Source: a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
Source: a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
Timeline
No history available yet.