Path Traversal Vulnerability in N-central by N-able
CVE-2024-8510

5.3MEDIUM

Key Information:

Vendor

N-able

Status
Vendor
CVE Published:
17 March 2025

What is CVE-2024-8510?

N-central, developed by N-able, is exposed to a path traversal vulnerability that permits unauthorized access to sensitive areas of the Apache Tomcat server, specifically the WEB-INF directory. This flaw could lead to exposure of internal files or resource paths, which might be exploited by an attacker to gather information about system internals. However, customer data remains secure as no user data is accessible through this vulnerability. It is crucial for users to update to N-central version 2024.6 or later to mitigate this risk effectively.

Affected Version(s)

N-central 0 < 2024.6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.