CVE-2020-25618
Summary
| CVE | CVE-2020-25618 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-16 14:15:00 UTC |
| Updated | 2020-12-21 16:16:00 UTC |
| Description | An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file). |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | N-central | 12.3.0.670 | All | All | All |
| Application | Solarwinds | N-central | 12.3.0.670 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisories for SolarWinds N-Central – Insinuator.net | MISC | insinuator.net | Third Party Advisory |
| Publications | ERNW - providing security. | MISC | ernw.de | Third Party Advisory |
| SolarWinds Product Support | Success Center | MISC | support.solarwinds.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.