N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed.
This vulnerability is present in all deployments of N-central prior to N-central 2024.6.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:* |
Tue, 18 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6. | |
| Title | N-central Path Traversal | |
| Weaknesses | CWE-22 CWE-23 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: N-able
Published: 2025-03-17T19:01:36.361Z
Updated: 2025-03-18T14:41:47.223Z
Reserved: 2024-09-06T12:54:48.767Z
Link: CVE-2024-8510
Updated: 2025-03-18T14:41:43.384Z
Status : Analyzed
Published: 2025-03-17T19:15:25.120
Modified: 2025-09-05T17:15:48.667
Link: CVE-2024-8510
No data.