N-Central
SolarWinds · 9 CVEs
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.
Dec 16, 2020
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: securit…
Dec 16, 2020
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user acco…
Dec 16, 2020
An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Chann…
Dec 16, 2020
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because…
Dec 16, 2020
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Trav…
Dec 16, 2020
SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possibl…
Oct 19, 2020
SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Ce…
Oct 19, 2020
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain a…
Jan 26, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-25622 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. | HIGH | 0.96% | Dec 16, 2020 |
| CVE-2020-25621 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a n… | HIGH | 0.54% | Dec 16, 2020 |
| CVE-2020-25620 | An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nablea… | HIGH | 0.43% | Dec 16, 2020 |
| CVE-2020-25619 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker ca… | MEDIUM | 0.45% | Dec 16, 2020 |
| CVE-2020-25618 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effective… | HIGH | 2.68% | Dec 16, 2020 |
| CVE-2020-25617 | An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-… | HIGH | 3.31% | Dec 16, 2020 |
| CVE-2020-15910 | SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascrip… | MEDIUM | 5.59% | Oct 19, 2020 |
| CVE-2020-15909 | SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not… | HIGH | 2.22% | Oct 19, 2020 |
| CVE-2020-7984 | SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe… | HIGH | 2.48% | Jan 26, 2020 |
Showing 1 to 9 of 9 CVEs