N Central
Vendor:
First CVE: Aug 4, 2023 · Active for 2 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
15.4%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact N Central over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 4, 2023
2 years ago
Most Recent CVE
Nov 12, 2025
254 days ago
CVE Severity & Scoring
N Central13 CVEs
15%
46%
38%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (23.1%)
Network10 (76.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (38.5%)
High0 (0.0%)
None8 (61.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8876HIGH Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. | Aug 14, 2025 | 8.8 | 73 | YES | NO |
CVE-2025-8875HIGH Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. | Aug 14, 2025 | 7.8 | 70 | YES | NO |
CVE-2025-9316MEDIUM N-central < 2025.4 can generate sessionIDs for unauthenticated users
This issue affects N-central: before 2025.4. | Nov 12, 2025 | 6.9 | 69 | NO | YES |
CVE-2025-11700HIGH N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure | Nov 12, 2025 | 7.5 | 67 | NO | YES |
CVE-2024-28200CRITICAL The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2.
This vulnerabi | Jul 1, 2024 | 9.8 | 39 | NO | YES |
CVE-2025-11367CRITICAL The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization | Nov 12, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-11366CRITICAL N-central < 2025.4 is vulnerable to authentication bypass via path traversal | Nov 12, 2025 | 9.8 | 32 | NO | NO |
CVE-2023-47132CRITICAL An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls. | Feb 8, 2024 | 9.8 | 28 | NO | NO |
CVE-2025-10231HIGH An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with el | Sep 10, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-7051HIGH On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all | Aug 21, 2025 | 8.3 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
2 CVEs
15.4% of CVEs· 98th percentile
Metasploit
2 CVEs
15.4% of CVEs· 97th percentile
Nuclei
3 CVEs
23.1% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For N Central
Top CWEs
Versions
No cataloged versions.