CRITICAL

CVE-2020-10148

Solarwinds Orion Platform 2020-12-29 CVSS v3.1
CVSS
9.8
KEV

Description

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

Summary dbcve.org

The SolarWinds Orion Platform contains an authentication bypass vulnerability in its API that allows remote attackers to bypass authentication mechanisms and execute arbitrary API commands, potentially leading to full system compromise.

Mitigation

Apply the available hotfixes (HF 5 for 2019.4, HF 2 for 2020.2) or upgrade to a patched version as specified in SolarWinds security advisory. Isolate affected systems from untrusted networks immediately if patching is delayed.

Weakness (CWE)

CWE-288
CWE-306 Missing Authentication

EPSS Score

91.98%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE