2N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verifying certificates of 2N edge devices.
CVE ID: CVE-2024-47258
CVSS Base Severity: HIGH
CVSS Base Score: 8.1
CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor: 2N
Product: 2N Access Commander
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.87% (scored less or equal to compared to others)
EPSS Date: 2025-03-07 (when was this score calculated)