Relative Path Traversal Vulnerability in SolarWinds N-Central
CVE-2020-25617

8.8HIGH

Key Information:

Vendor
Solarwinds
Status
Vendor
CVE Published:
16 December 2020

Summary

A relative path traversal vulnerability has been identified in SolarWinds N-Central 12.3.0.670. This issue allows an authenticated user of the N-Central Administration Console to manipulate HTTP requests, leading to the potential execution of operating system commands with root privileges. The flaw poses significant risks as it enables attackers to gain unauthorized access and control over the system, making it essential for users to apply relevant security measures and updates promptly.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.