CVE-2020-10148

CVE Published 2020-12-29
Related CWE(s) CWE-287: Improper Authentication, CWE-288: Authentication Bypass Using an Alternate Path or Channel
Related Vendor(s) solarwinds
Related Product(s) orion_platform
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References