2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices.
2N has currently released an updated version 3.3 of 2N Access Commander, with added Certificate Fingerprint Verification. Since version 2.2 of 2N Access Commander (released in February 2022) it is also possible to enforce TLS certificate validation.It is recommended that all customers update 2N Access Commander to the latest version and use one of two mentioned practices.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Feb 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. | 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. 2N has currently released an updated version 3.3 of 2N Access Commander, with added Certificate Fingerprint Verification. Since version 2.2 of 2N Access Commander (released in February 2022) it is also possible to enforce TLS certificate validation.It is recommended that all customers update 2N Access Commander to the latest version and use one of two mentioned practices. |
Thu, 06 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 06 Feb 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | 2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices. | |
Weaknesses | CWE-300 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Axis
Published: 2025-02-06T19:10:40.660Z
Updated: 2025-02-21T12:20:21.019Z
Reserved: 2024-09-23T16:37:50.255Z
Link: CVE-2024-47258

Updated: 2025-02-06T20:15:55.330Z

Status : Awaiting Analysis
Published: 2025-02-06T20:15:39.643
Modified: 2025-02-21T13:15:11.300
Link: CVE-2024-47258

No data.