CVE-2020-25620: High severity solarwinds vulnerability
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25620?
CVE-2020-25620 has a medium severity rating due to the presence of hard-coded credentials that can be exploited.
How do I fix CVE-2020-25620?
To fix CVE-2020-25620, replace the hard-coded credentials with secure, user-defined passwords for affected accounts.
What versions of SolarWinds N-Central are affected by CVE-2020-25620?
CVE-2020-25620 affects SolarWinds N-Central version 12.3.0.670.
What are the hard-coded credentials associated with CVE-2020-25620?
The hard-coded credentials associated with CVE-2020-25620 are for the local user accounts support@n-able.com and nableadmin@n-able.com.
What risks are posed by CVE-2020-25620?
The risks posed by CVE-2020-25620 include unauthorized access to the N-Central Administrative Console and potential compromise of system integrity.