CVE-2020-25617: Path Traversal
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of OS commands as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25617?
CVE-2020-25617 is classified as a high severity vulnerability due to its potential to allow unauthorized execution of OS commands.
How do I fix CVE-2020-25617?
To mitigate CVE-2020-25617, apply the latest security patches provided by SolarWinds for N-Central 12.3.0.670.
Who is affected by CVE-2020-25617?
CVE-2020-25617 affects users of SolarWinds N-Central version 12.3.0.670, specifically authenticated users of the N-Central Administration Console.
What type of vulnerability is CVE-2020-25617?
CVE-2020-25617 is a Relative Path Traversal vulnerability that can lead to OS command execution.
Can CVE-2020-25617 be exploited remotely?
CVE-2020-25617 requires authentication, meaning exploitation is limited to authenticated users of the N-Central Administration Console.