PT-2024-22335 · N-Central · N-Central
Aaron Miller
·
Published
2024-07-01
·
Updated
2025-12-24
·
CVE-2024-28200
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
N-central versions prior to 2024.2
Description
The issue concerns an authentication bypass of the user interface. It was discovered through an internal source code review, and there have been no observed exploitations in the wild.
Recommendations
For versions prior to 2024.2, update to version 2024.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the user interface until the update can be applied.
Fix
Authentication Bypass Using an Alternate Path or Channel
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
N-Central