Insecure Password Management in SolarWinds N-Able N-Central
CVE-2015-5610
Currently unrated
Summary
The RSM service within SolarWinds N-Able N-Central allows for potential exploitation due to its use of a static password decryption key across different customer installations. This design flaw permits remote authenticated users to uncover the cleartext domain-administrator password by accessing encrypted data through the HTML source code. As a result, knowledge of the decryption key from one installation can jeopardize the security of others, leading to unauthorized access and increased risk of system breaches.
References
Timeline
Vulnerability published
Vulnerability Reserved