CVE-2024-5445: Ecosystem Agent Insufficient Transport Layer Security
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5445?
CVE-2024-5445 is rated as a high-severity vulnerability due to insufficient SSL/TLS certificate validation.
How do I fix CVE-2024-5445?
To fix CVE-2024-5445, upgrade N-able Ecosystem Agent to version 4.1.5.2597 or higher, or to version 5.1.4.2473 or higher.
Which versions of Ecosystem Agent are affected by CVE-2024-5445?
CVE-2024-5445 affects Ecosystem Agent versions below 4.1.5.2597 and versions below 5.1.4.2473.
What does CVE-2024-5445 allow an attacker to do?
CVE-2024-5445 allows a malicious actor to perform a Man-in-the-Middle attack and intercept traffic between the agent and N-able servers.
Is there a known workaround for CVE-2024-5445?
There is no specific workaround for CVE-2024-5445, and the recommended action is to update the affected versions of the Ecosystem Agent.