Hard-Coded Credential Vulnerability in SolarWinds N-Central Software
CVE-2020-25620

7.8HIGH

Key Information:

Vendor
Solarwinds
Status
Vendor
CVE Published:
16 December 2020

Summary

A security issue has been identified in SolarWinds N-Central version 12.3.0.670, where hard-coded credentials for local user accounts (specifically [email protected] and [email protected]) are present by default. This flaw enables unauthorized access to the N-Central Administrative Console (NAC) and the standard web interface, posing a risk to the integrity of network management systems.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.