PT-2024-36335 · N Able · Ecosystem Agent

Published

2024-08-08

·

Updated

2025-01-07

·

CVE-2024-5445

CVSS v3.1

3.8

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Ecosystem Agent versions 4.0 through 4.1.5.2597 Ecosystem Agent versions 5.0 through 5.1.4.2473
Description: The issue is related to the improper validation of SSL/TLS certificates. This could allow a malicious actor to perform a Man-in-the-Middle attack and intercept traffic between the agent and N-able servers from a privileged network position.
Recommendations: For Ecosystem Agent versions 4.0 through 4.1.5.2597, update to version 4.1.5.2597 or later to resolve the issue. For Ecosystem Agent versions 5.0 through 5.1.4.2473, update to version 5.1.4.2473 or later to resolve the issue.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2024-5445

Affected Products

Ecosystem Agent