CVE-2024-28200
CRITICAL EXPLOITED IN THE WILD NUCLEIN-able N-central < 2024.2 - Authentication Bypass Detection
Title source: nucleiDescription
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
Nuclei Templates (1)
N-able N-central < 2024.2 - Authentication Bypass Detection
CRITICALVERIFIEDby rxerium
Shodan:
http.title:"N-central Login"
Scores
CVSS v3
9.1
EPSS
0.5292
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
VulnCheck KEV
2024-04-11
InTheWild.io
2024-07-01
CWE
CWE-287
CWE-288
Status
published
Products (1)
n-able/n-central
< 2024.2
Published
Jul 01, 2024
Tracked Since
Feb 18, 2026