Hard-Coded Credential Vulnerability in SolarWinds N-Central Software
CVE-2020-25620
7.8HIGH
Summary
A security issue has been identified in SolarWinds N-Central version 12.3.0.670, where hard-coded credentials for local user accounts (specifically [email protected] and [email protected]) are present by default. This flaw enables unauthorized access to the N-Central Administrative Console (NAC) and the standard web interface, posing a risk to the integrity of network management systems.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved