CVE-2024-5445: Ecosystem Agent Insufficient Transport Layer Security

Published Aug 8, 2024
·
Updated

Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.

Affected Software

1 affected component
N-able Ecosystem Agent<4.1.5.2597, <5.1.4.2473

Remediation

Information

Ecosystem Agents have been updated automatically. Check that the Ecosystem Agent has been updated to v4.5.1.2597 for version 4 agents or v5.1.4273 for version 5 agents or newer. Please review the referenced knowledge base articles for checking Ecosystem agent version numbers and contact support if the agent hasn't updated.

Event History

Aug 8, 2024
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
RemedyDescriptionSeverityWeakness
Aug 12, 2024
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-5445?

CVE-2024-5445 is rated as a high-severity vulnerability due to insufficient SSL/TLS certificate validation.

2

How do I fix CVE-2024-5445?

To fix CVE-2024-5445, upgrade N-able Ecosystem Agent to version 4.1.5.2597 or higher, or to version 5.1.4.2473 or higher.

3

Which versions of Ecosystem Agent are affected by CVE-2024-5445?

CVE-2024-5445 affects Ecosystem Agent versions below 4.1.5.2597 and versions below 5.1.4.2473.

4

What does CVE-2024-5445 allow an attacker to do?

CVE-2024-5445 allows a malicious actor to perform a Man-in-the-Middle attack and intercept traffic between the agent and N-able servers.

5

Is there a known workaround for CVE-2024-5445?

There is no specific workaround for CVE-2024-5445, and the recommended action is to update the affected versions of the Ecosystem Agent.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203