Skip to content
COOEY

EXPOSURES › CVE-2020-10148

CVE-2020-10148

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-10148 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrcenegligence

SolarWinds Orion API authentication bypass allowed remote attackers to execute arbitrary commands without valid credentials.

The Orion API lacked proper authentication validation, enabling unauthenticated remote command execution. DIBs must verify API authentication controls and patch legacy SolarWinds instances, as this flaw was actively exploited in the wild to compromise networks.

Shame score — A critical authentication bypass in a widely deployed monitoring platform was actively exploited in the wild, causing massive network compromises and severe reputational damage.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
SolarWinds' authentication bypass flaw was widely condemned as a critical systemic failure, though the provided sources lack direct commentary on the vendor's response or specific fallout details beyo
cooey ↗ severe-fallout -0.60
Technical description of a critical flaw without commentary on vendor response; implies severe risk.
"SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands."
NVD ↗ severe-fallout +0.00
Irrelevant NVD page with no mention of SolarWinds or CVE-2020-10148.
portswigger.net ↗ severe-fallout +0.00
Irrelevant Burp Scanner documentation page with no mention of SolarWinds or CVE-2020-10148.
www.nbcnews.com ↗ severe-fallout +0.00
Irrelevant NBC News article with no mention of SolarWinds or CVE-2020-10148.
www.cvefind.com ↗ severe-fallout +0.00
Irrelevant CVE database page with no mention of SolarWinds or CVE-2020-10148.
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Irrelevant Cisco security advisory page with no mention of SolarWinds or CVE-2020-10148.
recentbreaches.com ↗ severe-fallout +0.00
Irrelevant breach tracker page with no mention of SolarWinds or CVE-2020-10148.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.