CVE-2020-10148
Description
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
Summary dbcve.org
The SolarWinds Orion Platform contains an authentication bypass vulnerability in its API that allows remote attackers to bypass authentication mechanisms and execute arbitrary API commands, potentially leading to full system compromise.
Mitigation
Apply the available hotfixes (HF 5 for 2019.4, HF 2 for 2020.2) or upgrade to a patched version as specified in SolarWinds security advisory. Isolate affected systems from untrusted networks immediately if patching is delayed.