ASD warns of Australian attacks on N-able N-central RMM

Key points

The Australian Cyber Security Centre has observed attackers targeting vulnerabilities in N-able N-central, putting MSPs and client networks at risk.

ASD warns of Australian attacks on N-able N-central RMM

ASD warns of Australian attacks on N-able N-central RMM

Key points

  • The Australian Cyber Security Centre has observed attackers targeting vulnerabilities in N-able N-central, putting MSPs and client networks at risk.
  • N-able disclosed a critical authentication vulnerability in early August that can grant “god mode” access to the RMM console on hosted and on-premises instances.
  • N-able has issued two hotfixes for the actively exploited flaw, and users are advised to apply them immediately and monitor for suspicious activity.




ASD warns of Australian attacks on N-able N-central RMM










The Australian Cyber Security Centre said it has observed attackers targeting vulnerabilities in N-able N-central, putting managed service providers (MSPs) and client networks they administer at risk.

N-central is a remote monitoring and management (RMM) platform that MSPs and large enterprise IT departments use to discover, manage, automate and secure endpoints and network infrastructure.

The company behind it, N-able, disclosed a critical authentication vulnerability in N-central at the beginning of August which, if exploited, provides “god mode” access to the RMM console on both hosted and on-premises instances, security vendor Huntress wrote in its analysis.

Huntress said the vulnerability is actively exploited, with ASD’s ACSC now warning about the same for Australia.

N-able has issued hotfixes for the vulnerability which users are advised to apply immediately.

“A threat actor exploited a vulnerability in N‑central that allowed remote administrative access without authentication,” N-able said in its August 10 security update.

“Once inside, they used N‑central’s Take Control feature to connect to managed devices, and registered Cloudflare tunnel services on those devices to maintain persistence even after their access to N‑central was revoked.

“Hotfix 1 addressed the original access point. Continued monitoring identified a related attack path, which Hotfix 2 addresses with additional hardening,” 

ACSC advises users to check their networks and environments for use of vulnerable versions of the N-able N-central product, and whether or not there is a need to continue to have the interface for the RMM exposed to the internet.

Users are also advised to contact their MSPs and enterprise IT providers to ensure managed N-able N-central instances are patched, with monitoring for suspicious activity.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.