CVE-2020-10148
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- SolarWinds Orion Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 92% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-288, CWE-306
מוצרים מושפעים
solarwinds: orion platform
קישורים
- https://www.solarwinds.com/securityadvisory Vendor Advisory
- https://www.solarwinds.com/securityadvisory Vendor Advisory
- https://kb.cert.org/vuls/id/843464 Third Party AdvisoryUS Government Resource
- https://kb.cert.org/vuls/id/843464 Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/843464 Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource