CVE-2020-25621 Information
Jun 07, 2022
cve
Description
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://ernw.de/en/publications.html https://support.solarwinds.com/SuccessCenter/s/ https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.4
Share on: