CVE-2020-25619: Medium severity solarwinds vulnerability
An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwarding with a temporary key pair) to access network services on the 127.0.0.1 interface, even though this feature was only intended for user-to-agent communication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25619?
The severity of CVE-2020-25619 is classified as high due to the potential for unauthorized access to network services.
How do I fix CVE-2020-25619?
To fix CVE-2020-25619, you should update SolarWinds N-Central to a version that mitigates the SSH component vulnerability.
What does CVE-2020-25619 affect?
CVE-2020-25619 affects SolarWinds N-Central version 12.3.0.670 specifically.
Can CVE-2020-25619 be exploited remotely?
Yes, CVE-2020-25619 can be exploited remotely by leveraging SSH features like port forwarding.
What are the consequences of CVE-2020-25619 exploitation?
Exploitation of CVE-2020-25619 can allow attackers to gain unauthorized access to restricted network services.