๐Ÿ” CVE Alert

CVE-2025-7051

HIGH 8.3

N-central Syslog Configuration Insecure Direct Object Reference

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.

CWE CWE-284
Vendor n-able
Product n-central
Published Aug 21, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for n-able n-central

Be the first to know when new high vulnerabilities affecting n-able n-central are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

N-able / N-central
2024.6.0 โ‰ค 2024.6.16 2025.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
documentation.n-able.com: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2025.2_Release_Notes.htm