{"api_version":"1","generated_at":"2026-07-24T18:27:05+00:00","cve":"CVE-2020-25618","urls":{"html":"https://cve.report/CVE-2020-25618","api":"https://cve.report/api/cve/CVE-2020-25618.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-25618","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-25618"},"summary":{"title":"CVE-2020-25618","description":"An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-12-16 14:15:00","updated_at":"2020-12-21 16:16:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/","name":"https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Security Advisories for SolarWinds N-Central – Insinuator.net","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://ernw.de/en/publications.html","name":"https://ernw.de/en/publications.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"Publications | ERNW - providing security.","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://support.solarwinds.com/SuccessCenter/s/","name":"https://support.solarwinds.com/SuccessCenter/s/","refsource":"MISC","tags":["Vendor Advisory"],"title":"SolarWinds Product Support | Success Center","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-25618","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25618","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"25618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"solarwinds","cpe5":"n-central","cpe6":"12.3.0.670","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"25618","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"solarwinds","cpe5":"n-central","cpe6":"12.3.0.670","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-25618","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://support.solarwinds.com/SuccessCenter/s/","refsource":"MISC","name":"https://support.solarwinds.com/SuccessCenter/s/"},{"url":"https://ernw.de/en/publications.html","refsource":"MISC","name":"https://ernw.de/en/publications.html"},{"refsource":"MISC","name":"https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/","url":"https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/"}]}},"nvd":{"publishedDate":"2020-12-16 14:15:00","lastModifiedDate":"2020-12-21 16:16:00","problem_types":["CWE-78"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:solarwinds:n-central:12.3.0.670:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"25618","Ordinal":"187035","Title":"CVE-2020-25618","CVE":"CVE-2020-25618","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"25618","Ordinal":"1","NoteData":"An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).","Type":"Description","Title":null},{"CveYear":"2020","CveId":"25618","Ordinal":"2","NoteData":"2020-12-16","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"25618","Ordinal":"3","NoteData":"2020-12-16","Type":"Other","Title":"Modified"}]}}}