CVE-2020-25618: OS Command Injection
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25618?
The severity of CVE-2020-25618 is critical.
What is the affected software by CVE-2020-25618?
The affected software by CVE-2020-25618 is SolarWinds N-Central 12.3.0.670.
How does CVE-2020-25618 impact the sudo configuration?
CVE-2020-25618 impacts the sudo configuration by allowing the nable web user account to run arbitrary OS commands as root.
Is there a fix available for CVE-2020-25618?
Yes, a fix is available for CVE-2020-25618. It is recommended to update to a version of SolarWinds N-Central that is not affected by the vulnerability.
Where can I find more information about CVE-2020-25618?
You can find more information about CVE-2020-25618 in the references provided: [1](https://ernw.de/en/publications.html), [2](https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/), [3](https://support.solarwinds.com/SuccessCenter/s/)