Skip to main content

Vendor/product archive

solarwinds / n-central CVEs

Beta · best-effort

9 CVEs tagged to solarwinds / n-central0 Critical, 7 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2020-25622

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25621

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. Th…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25619

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH fe…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25618

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25617

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administrati…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15910

Published Oct 19, 2020

SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15909

Published Oct 19, 2020

SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against mul…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7984

Published Jan 26, 2020

SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1