CVE-2025-8875

HIGH(7.8)KEV

N-able N-Central Insecure Deserialization Vulnerability

Beschreibung

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

KEV-Informationen

Hersteller
N-able
Produkt
N-Central
Hinzugefügt am
13. August 2025
Fälligkeitsdatum
20. August 2025
Erforderliche Maßnahme
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnen
Angriffsvektor
LOCAL
Angriffskomplexität
LOW
Erforderliche Privilegien
LOW
Benutzerinteraktion
NONE
Scope
UNCHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
HIGH
Verfügbarkeitsauswirkung
HIGH
Ausnutzbarkeitsscore
1.8
Auswirkungsscore
5.9

CWEs

Betroffene Produkte

HerstellerProduktVersion
n-ablen-central< 2025.3.1

Referenzen

CVSS-Score

7.8
HIGH(7.8)

EPSS-Score

EPSS-Score1.59%
EPSS-Perzentil73.1%

Daten

Veröffentlicht14. August 2025
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.