CVE-2024-5322
CRITICALn-able n-central < 2024.3 - Authentication Bypass via Entra SSO Session Rebinding
Title source: llmDescription
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
References (2)
Core 2
Scores
CVSS v3
9.1
EPSS
0.0041
EPSS Percentile
32.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-288
Status
published
Products (1)
n-able/n-central
< 2024.3
Published
Jul 01, 2024
Tracked Since
Feb 18, 2026