First published: Wed Dec 16 2020(Updated: )
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds N-Central | =12.3.0.670 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25620 has a medium severity rating due to the presence of hard-coded credentials that can be exploited.
To fix CVE-2020-25620, replace the hard-coded credentials with secure, user-defined passwords for affected accounts.
CVE-2020-25620 affects SolarWinds N-Central version 12.3.0.670.
The hard-coded credentials associated with CVE-2020-25620 are for the local user accounts support@n-able.com and nableadmin@n-able.com.
The risks posed by CVE-2020-25620 include unauthorized access to the N-Central Administrative Console and potential compromise of system integrity.