Rapid7
Critical Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The SolarWinds Orion API is vulnerable to an authentication bypass, allowing remote attackers to execute API commands without authentication. This vulnerability, identified as CVE-2020-10148, can be exploited by appending specific parameters to the Request.PathInfo portion of a URI request. Affected versions include SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix, and 2020.2 HF 1. The vulnerability has been actively exploited in the wild, and organizations are urged to update to patched versions released in December 2020. The flaw is linked to the installation of the SUPERNOVA malware. Security advisories and mitigations have been issued, including hardening IIS servers. Users are encouraged to apply updates promptly to protect their systems.
Key Points: • CVE-2020-10148 allows unauthenticated remote code execution via SolarWinds Orion API. • Affected versions include 2019.4 HF 5 and 2020.2 without hotfixes. • Immediate patching is critical due to active exploitation of this vulnerability.