CVE-2024-5445: N-able Ecosystem Agent
Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers from a privileged network position.
Affected products
- N-able Ecosystem Agent: before 4.1.5.2597 (fixed in 4.1.5.2597); before 5.1.4.2473 (fixed in 5.1.4.2473)
Published 2024-08-12. Last modified 2026-06-17.