Dive Brief:
- N-able alerted customers to a critical zero-day vulnerability and two additional security issues in its N-central remote monitoring and management platform over the Labor Day holiday weekend. N-central functions as a unified endpoint management and RMM console for more than 500,000 IT teams and managed service providers.
- The vendor issued hotfixes on Saturday for two registered Common Vulnerabilities and Exposures identified by Rapid7 Labs and Huntress. N-able deployed a third patch Sunday after an undisclosed third-party discovered an additional vulnerability that “could allow pre-authenticated access to the N-central server,” the company said.
- N-able urged MSPs, businesses and other organizations using N-central on-premises to upgrade to the latest version immediately, install the hotfixes, review logs for scanning activity and audit user accounts. Customers running the platform in hosted cloud environments received automatic patches but were advised to run security checks.
Dive Insight:
N-able has been busy bolstering N-central’s defenses for more than a month. The company issued two urgent security fixes in early August, just days after it released the current version of the RMM platform.
On Saturday, Huntress disclosed additional vulnerabilities discovered by a team working on prior breaches, according to Principal Tactical Response Analyst Michael Tigges.
“Because of the research, we were able to probe into the N-Central codebase after further unexplained exploitation and discover the vulnerabilities we reported,” Tigges told Channel Dive. “The exploit we developed was directly related to the original vulnerabilities at the beginning of August.”
RMM and UEM platforms let IT services providers scale operations remotely across multiple clients. They also create appealing points of attack for bad actors. Unauthorized users with access to an N-central server can run scripts, push tools and open remote sessions across managed endpoints, Huntress researchers found.
“Platforms represent the keys to the kingdom,” Tigges said. “Ultimately, it's a balance of convenience versus security — one that's vexed cybersecurity professionals for decades.”
Earlier this month, Huntress detected anomalous activity in the ConnectWise RMM platform ScreenConnect. ConnectWise issued a Sept. 4 alert promising an official fix within a week.
While the ScreenConnect anomalies were distinct from N-connect’s vulnerabilities, the two discoveries underscore a broader trend that’s particularly worrisome for MSPs and small and midsize businesses.
“RMMs are increasingly becoming a common attack vector for adversaries, especially in the SMB segment,” Tigges said. “We cannot predict vulnerabilities, but we can instrument heavily enough to detect likely exploitation when it does occur.”
N-able acted quickly to address the N-connect vulnerabilities and is counting on its customers to follow suit.
“Security is a continuous responsibility, not a single event,” the company told Channel Dive in an email. “This is one part of a broader, ongoing effort and doesn’t stop with a hotfix. N-able is continuing to invest in improving the resilience of N-central's architecture and expanding proactive threat detection.”