CVE-2020-7984: High severity SolarWinds N-Central vulnerability
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any aspects of the agent/appliance configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds N-centralto a version that resolves this vulnerability.Fixed in 12.1 SP1 HF5
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7984?
CVE-2020-7984 is rated as high severity due to the potential exposure of sensitive domain admin credentials.
How do I fix CVE-2020-7984?
To fix CVE-2020-7984, upgrade SolarWinds N-central to version 12.1 SP1 HF5 or 12.2 SP1 HF2 or later.
What types of information can be accessed through CVE-2020-7984?
CVE-2020-7984 allows attackers to access cleartext domain admin credentials and other sensitive information from the Agent & Probe settings.
Who is affected by CVE-2020-7984?
Users of SolarWinds N-central versions prior to 12.1 SP1 HF5 and 12.2 SP1 HF2 are affected by CVE-2020-7984.
Can CVE-2020-7984 be exploited remotely?
Yes, CVE-2020-7984 can be exploited remotely, enabling attackers to retrieve sensitive information.