Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.
References
Configurations
No configuration.
History
07 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position. |
12 Aug 2024, 13:41
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-12 13:38
Updated : 2025-01-07 20:15
NVD link : CVE-2024-5445
Mitre link : CVE-2024-5445
CVE.ORG link : CVE-2024-5445
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation