N-able Bug Exposes Password Vault Master Keys
Summary
A bug in N-able's Passportal password manager, used by MSPs and SMBs, exposed master keys to its password vault. While a patch has been released, the cloud-based nature of the product continues to pose risks.
IFF Assessment
The vulnerability allows for the potential exposure of sensitive credentials, which is bad news for defenders managing and using the affected product.
Severity
The vulnerability allows for unauthorized access to a password vault's master keys, which can lead to the compromise of all stored credentials, indicating a high impact.
Defender Context
This vulnerability highlights the ongoing risks associated with cloud-hosted password managers, even after patches. Defenders should be wary of potential supply chain risks when using third-party managed services and ensure robust security practices are in place for cloud-based tools.