CVE-2024-8510 Details
Description
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.
A path traversal vulnerability has been identified in N-central, allowing unauthorized access to the Apache Tomcat WEB-INF directory. This issue affects all N-central deployments prior to version 2024.6. While customer data is not exposed, the vulnerability could be exploited to access sensitive application files or configurations.
Users can upgrade to N-central version 2024.6 or higher to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2024.6_Release_Notes.htm | N-able | Release Notes |
| https://me.n-able.com/s/security-advisory/aArVy0000000XgjKAE/cve20248510-ncentral-path-traversal | N-able | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | N-able |
| CWE-23 | Relative Path Traversal | N-able |
Affected Products
| Product | Versions |
|---|---|
| n-able n-central | < 2024.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | N-able |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2025 | Initial Analysis | [email protected] |
| Mar 17, 2025 | New CVE Received | N-able |