CVE-2023-37244

MEDIUM

N-able Automation Manager < 2.91.0.0 - Race Condition

Title source: rule
STIX 2.1

Description

The affected AutomationManager.AgentService.exe application contains a TOCTOU race condition vulnerability that allows standard users to create a pseudo-symlink at C:\ProgramData\N-Able Technologies\AutomationManager\Temp, which could be leveraged by an attacker to manipulate the process into performing arbitrary file deletions. We recommend upgrading to version 2.91.0.0

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-362
Status published
Products (1)
n-able/automation_manager < 2.91.0.0
Published May 02, 2024
Tracked Since Feb 18, 2026