PT-2025-5860 · 2N · 2N Access Commander
Published
2025-02-06
·
Updated
2025-02-21
·
CVE-2024-47258
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
2N Access Commander versions 2.1 and prior
Description
The issue is related to a Man In The Middle attack due to the software not verifying certificates of 2N edge devices in default settings.
Recommendations
For 2N Access Commander versions 2.1 and prior, consider updating the configuration to verify certificates of 2N edge devices to prevent Man In The Middle attacks. As a temporary workaround, restrict access to the default settings until a proper fix is applied.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
2N Access Commander