A critical vulnerability was discovered by N-Able in it's product N-Central, a remote management appliance used for IT administration.
The Vulnerability
The vulnerability was already being exploited at the time of discovery and exploitation is reportedly continuing at the time of writing.Following exploitation, attackers abused built-in functionality to take full control of highly sensitive machines in the environment, including domain controllers, which manage the security and identities for the entire network.
Several factors greatly increase the risk of exploitation and malicious activity:
- The N-Central server version is < 2026.3.1.7. This is the patch which fixes the vulnerability and should be applied immediately.
- The appliance's management interface is exposed to the internet. Generally, this goes against security recommendations
- The N-Central RMM software is in use on critical endpoints, such as domain controllers or file servers.
- A lack of strong security controls in associated networks, such as MFA on active directory accounts.
- A lack of Endopint Detection and Response technology in the environment which could detect malicious behaviour.
Remediation
If an un-patched appliance has been exposed to the internet, customers should perform manual checks for non-standard authentications and behaviour within associated networks.
N-Able released a set of IP addresses used in previously observed attacks. These should be blocked and attempted connections monitored:
-
173[.]249[.]252[.]200
-
87[.]249[.]138[.]34
-
37[.]19[.]210[.]32
-
37[.]153[.]90[.]88
-
92[.]118[.]112[.]181
-
68[.]235[.]46[.]214
If you believe your network may have been affected by this vulnerability, or are not sure, contact the Integrity360 Incident Response team for assistance.
