Vulnerability Description
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://me.n-able.com/s/article/How-to-check-Ecosystem-Agent-Version-in-N-sight
- https://me.n-able.com/s/article/How-to-check-Ecosystem-Agent-version-in-N-centra
- https://me.n-able.com/s/security-advisory/aArVy0000000BhpKAE/cve20245445-ecosyst
FAQ
What is CVE-2024-5445?
CVE-2024-5445 is a vulnerability with a CVSS score of 3.8 (LOW). Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and...
How severe is CVE-2024-5445?
CVE-2024-5445 has been rated LOW with a CVSS base score of 3.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5445?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.