CVE-2025-7051 Details
Description
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
A vulnerability exists in N-able N-central in all versions prior to 2025.2, allowing any authenticated user to read, write, and modify syslog configurations across different customers on the same N-central server. This issue arises from improper access controls, enabling unauthorized changes to syslog settings, which could lead to misconfigured log exports and potential oversight of critical audit events.
Users are advised to upgrade to N-able N-central version 2025.2 or later, which addresses this vulnerability. Instructions for upgrading N-central can be found in the N-able N-central Upgrade Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2025.2_Release_Notes.htm | N-able | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | N-able |
Affected Products
| Product | Versions |
|---|---|
| n-able n-central | < 2025.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | N-able |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2025 | Initial Analysis | [email protected] |
| Aug 21, 2025 | New CVE Received | N-able |