CVE-2020-10148
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
- Affected products
- Solarwinds Orion Platform
- Solarwinds Orion Platform
- = 2019.4, 2020.2, 2020.2.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 92.0% (100th percentile)
- Weakness
- CWE-306, CWE-288
- NVD status
- Analyzed
- Published
- 2020-12-29
Fix
Users should update to the relevant versions of the SolarWinds Orion Platform: 2019.4 HF 6 (released December 14, 2020) 2020.2.1 HF 2 (released December 15, 2020) 2019.2 SUPERNOVA Patch (released December 23, 2020) 2018.4 SUPERNOVA Patch (released December 23, 2020) 2018.2 SUPERNOVA Patch (released December 23, 2020)
3 known exploits for CVE-2020-10148
Proof-of-concept code and exploit modules indexed by Sploitus