First published: Wed Jun 24 2020(Updated: )
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Orion Network Performance Monitor | =2019.4-hotfix2 | |
Solarwinds Orion Web Performance Monitor | =2019.4.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14005 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor.
CVE-2020-14005 has a severity rating of 8.8, which is classified as critical.
CVE-2020-14005 exploits the vulnerability by taking advantage of the ExecuteExternalProgram method in SolarWinds Network Performance Monitor.
To fix CVE-2020-14005, it is recommended to apply the necessary patches or updates provided by SolarWinds.
You can find more information about CVE-2020-14005 on the following sources: [1] [2] [3]