First published: Wed Dec 16 2020(Updated: )
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of OS commands as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds N-Central | =12.3.0.670 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25617 is classified as a high severity vulnerability due to its potential to allow unauthorized execution of OS commands.
To mitigate CVE-2020-25617, apply the latest security patches provided by SolarWinds for N-Central 12.3.0.670.
CVE-2020-25617 affects users of SolarWinds N-Central version 12.3.0.670, specifically authenticated users of the N-Central Administration Console.
CVE-2020-25617 is a Relative Path Traversal vulnerability that can lead to OS command execution.
CVE-2020-25617 requires authentication, meaning exploitation is limited to authenticated users of the N-Central Administration Console.