CVE-2025-7051: N-central Syslog Configuration Insecure Direct Object Reference
Published Aug 21, 2025
·Updated
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
Affected Software
2 affected components
N-able N-Central<2025.2
N-able N-Central<2025.2
Remediation
Information
Upgrade to N-central version 2025.2 or higher.
Event History
Aug 21, 2025
CVE Published
via MITRE·05:34 PM
Data Sourced
via MITRE·05:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-7051?
CVE-2025-7051 has a high severity rating due to the potential for authenticated users to modify syslog configurations across customer accounts.
2
How do I fix CVE-2025-7051?
To fix CVE-2025-7051, upgrade your N-central deployment to version 2025.2 or later.
3
Who is affected by CVE-2025-7051?
All users of N-able N-central prior to version 2025.2 are affected by CVE-2025-7051.
4
What type of vulnerability is CVE-2025-7051?
CVE-2025-7051 is an access control vulnerability that allows unauthorized modification of syslog configurations.
5
Can an unauthenticated user exploit CVE-2025-7051?
No, only authenticated users can exploit CVE-2025-7051 to access and modify syslog configurations.