PT-2024-36335 · N Able · Ecosystem Agent
Published
2024-08-08
·
Updated
2025-01-07
·
CVE-2024-5445
CVSS v3.1
3.8
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Ecosystem Agent versions 4.0 through 4.1.5.2597
Ecosystem Agent versions 5.0 through 5.1.4.2473
Description:
The issue is related to the improper validation of SSL/TLS certificates. This could allow a malicious actor to perform a Man-in-the-Middle attack and intercept traffic between the agent and N-able servers from a privileged network position.
Recommendations:
For Ecosystem Agent versions 4.0 through 4.1.5.2597, update to version 4.1.5.2597 or later to resolve the issue.
For Ecosystem Agent versions 5.0 through 5.1.4.2473, update to version 5.1.4.2473 or later to resolve the issue.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecosystem Agent