N-central Server Vulnerable to Session Rebinding, Affecting All Entra-Supported Deployments
CVE-2024-5322
What is CVE-2024-5322?
The N-central server by N-able is vulnerable to a session rebinding issue that targets authenticated users utilizing Entra Single Sign-On (SSO) functionality. This vulnerability poses a risk by potentially allowing unauthorized access through authentication bypass. It is crucial to note that this vulnerability affects all N-central deployments that are compatible with Entra and have not been updated to version 2024.3 or later. Organizations using older versions of N-central are encouraged to assess their exposure and take necessary actions to remediate this security concern promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
N-central <2024.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
