CVE-2025-7051

On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*

History

08 Sep 2025, 16:15

Type Values Removed Values Added
First Time N-able
N-able n-central
CPE cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*
References () https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2025.2_Release_Notes.htm - () https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2025.2_Release_Notes.htm - Release Notes

22 Aug 2025, 18:08

Type Values Removed Values Added
Summary
  • (es) En N-central, cualquier usuario autenticado puede leer, escribir y modificar la configuración de syslog de los clientes en un servidor N-central. Esta vulnerabilidad está presente en todas las implementaciones de N-central anteriores a la versión 2025.2.

21 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 18:15

Updated : 2025-09-08 16:15


NVD link : CVE-2025-7051

Mitre link : CVE-2025-7051

CVE.ORG link : CVE-2025-7051


JSON object : View

Products Affected

n-able

  • n-central
CWE
CWE-284

Improper Access Control