Sploitus

CVE-2020-10148

3 known exploits for CVE-2020-10148

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

Affected products
Solarwinds Orion Platform
Solarwinds Orion Platform
= 2019.4, 2020.2, 2020.2.1
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
92.0% (100th percentile)
Weakness
CWE-306, CWE-288
NVD status
Analyzed
Published
2020-12-29

Fix

Users should update to the relevant versions of the SolarWinds Orion Platform: 2019.4 HF 6 (released December 14, 2020) 2020.2.1 HF 2 (released December 15, 2020) 2019.2 SUPERNOVA Patch (released December 23, 2020) 2018.4 SUPERNOVA Patch (released December 23, 2020) 2018.2 SUPERNOVA Patch (released December 23, 2020)

CVE-2020-10148 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2020-10148

Proof-of-concept code and exploit modules indexed by Sploitus