Critical Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)
ID: c1dcaca8-4517-5055-b0bc-e2847952e117
STIX ID: report--c1dcaca8-4517-5055-b0bc-e2847952e117
Feed Name: ThreatCluster
Threat Score
The report details CVE-2020-10148, an authentication bypass in the SolarWinds Orion API that enables unauthenticated remote code execution by appending specific parameters to Request.PathInfo; affected versions include 2019.4 HF 5 and 2020.2 (without hotfix), the flaw was actively exploited in the wild and linked to the SUPERNOVA malware, and organizations are urged to apply December 2020 patches and harden IIS servers immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
