U.S. CISA adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalog
美国网络安全与基础设施安全局(CISA)将N-able N-Central平台的两个安全漏洞(CVE-2025-8875和CVE-2025-8876)加入其已知被利用的漏洞目录。这些漏洞涉及反序列化和命令注入问题,已在N-Central 2025.3.1版本中修复。CISA要求联邦机构于2025年8月20日前完成修补以应对潜在威胁。 2025-8-14 08:2:22 Author: securityaffairs.com(查看原文) 阅读量:13 收藏

U.S. CISA adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added N-able N-Central flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-8875 N-able N-central Insecure Deserialization Vulnerability
  • CVE-2025-8876 N-able N-central Command Injection Vulnerability

N-able N-central is an Remote Monitoring and Management (RMM) platform for MSPs to centrally manage and secure Windows, Apple, and Linux endpoints.

GA of N-central 2025.3.1 address both vulnerabilities.

“This release includes a critical security fix for CVE-2025-8875 and CVE-2025-8876. These vulnerabilities require authentication to exploit.” reads the advisory. “However, there is a potential risk to the security of your N-central environment, if unpatched. You must upgrade your on-premises N-central to 2025.3.1.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by August 20, 2025.

Yesterday, U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities catalog.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cisa)




文章来源: https://securityaffairs.com/181135/security/u-s-cisa-adds-n-able-n-central-flaws-to-its-known-exploited-vulnerabilities-catalog.html
如有侵权请联系:admin#unsafe.sh