N-able Bug Exposes Password Vault Master Keys

Summary

A bug in N-able's Passportal password manager, used by MSPs and SMBs, exposed master keys to its password vault. While a patch has been released, the cloud-based nature of the product continues to pose risks.

IFF Assessment

FOE

The vulnerability allows for the potential exposure of sensitive credentials, which is bad news for defenders managing and using the affected product.

Severity

9.0 Critical (AI Estimated)

The vulnerability allows for unauthorized access to a password vault's master keys, which can lead to the compromise of all stored credentials, indicating a high impact.

Defender Context

This vulnerability highlights the ongoing risks associated with cloud-hosted password managers, even after patches. Defenders should be wary of potential supply chain risks when using third-party managed services and ensure robust security practices are in place for cloud-based tools.

Read Full Story →