Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:NDefault status
unaffected
Any version before 3.5
affected
Description
Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.
Problem types
CWE-1286 – Improper Validation of Syntactic Correctness
Product status
Any version before 3.5
References
www.2n.com/en-GB/download/cve_2025_59785_acom_3_5_v1pdf