CVE-2018-16791 Information
Feb 14, 2021
cve
Description
In SolarWinds SFTP/SCP Server through 2018-09-10 the configuration file is world readable and writable and stores user passwords in an insecure manner allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://seclists.org/fulldisclosure/2018/Dec/0
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: