First published: Wed Dec 16 2020(Updated: )
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds N-Central | =12.3.0.670 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-25618 is critical.
The affected software by CVE-2020-25618 is SolarWinds N-Central 12.3.0.670.
CVE-2020-25618 impacts the sudo configuration by allowing the nable web user account to run arbitrary OS commands as root.
Yes, a fix is available for CVE-2020-25618. It is recommended to update to a version of SolarWinds N-Central that is not affected by the vulnerability.
You can find more information about CVE-2020-25618 in the references provided: [1](https://ernw.de/en/publications.html), [2](https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/), [3](https://support.solarwinds.com/SuccessCenter/s/)