Junglewise Threat Intelligence

CVE-2020-10148: SolarWinds Orion Authentication Bypass Vulnerability

CVE-2020-10148 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: SolarWinds.

Executive brief

The SolarWinds Orion API contains an authentication bypass vulnerability that allows a remote attacker to execute API commands without authentication. This flaw can lead to a full compromise of the affected SolarWinds instance.

Affected products

  • SolarWinds Orion Platform 2019.4 HF 5, 2020.2, 2020.2 HF 1

Timeline

  • 2020-12-29: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory