CVE-2020-10148: SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
Other sources
SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Orion Platformto a version that resolves this vulnerability.Fixed in 2018.2 SUPERNOVA Patch - Upgrade
Upgrade
SolarWinds Orion Platformto a version that resolves this vulnerability.Fixed in 2018.4 SUPERNOVA Patch - Upgrade
Upgrade
SolarWinds Orion Platformto a version that resolves this vulnerability.Fixed in 2019.2 SUPERNOVA Patch - Upgrade
Upgrade
SolarWinds Orion Platformto a version that resolves this vulnerability.Fixed in 2019.4 HF 6 - Upgrade
Upgrade
SolarWinds Orion Platformto a version that resolves this vulnerability.Fixed in 2020.2.1 HF 2
Event History
Frequently Asked Questions
What is CVE-2020-10148?
CVE-2020-10148 is a vulnerability in SolarWinds Orion that allows an attacker to bypass authentication and execute API commands.
How do I know if my SolarWinds Orion instance is affected?
Check if you are using SolarWinds Orion 2019.4-hotfix5, 2020.2, or 2020.2.1-hotfix1.
What is the severity level of CVE-2020-10148?
CVE-2020-10148 has a severity level of 9.8, which is considered critical.
How can this vulnerability be exploited?
An attacker can exploit CVE-2020-10148 by bypassing authentication and executing API commands remotely.
Where can I find more information about CVE-2020-10148?
You can find more information about CVE-2020-10148 in the CERT Vulnerability Note and SolarWinds security advisory.