8.3
CVE-2025-7051
- EPSS 0.26%
- Veröffentlicht 21.08.2025 17:34:31
- Zuletzt bearbeitet 08.09.2025 16:15:50
- Quelle a5532a13-c4dd-4202-bef1-e0b8f2
- CVE-Watchlists
- Unerledigt
N-central Syslog Configuration Insecure Direct Object Reference
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.166 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| a5532a13-c4dd-4202-bef1-e0b8f2f8d12b | 8.3 | 2.8 | 5.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2025.2_Release_Notes.htm