EXPOSURES › CVE-2020-10148
CVE-2020-10148
HIGH ⌖ ON CISA KEV · EXPLOITEDSolarWinds Orion API authentication bypass allowed remote attackers to execute arbitrary commands without valid credentials.
The Orion API lacked proper authentication validation, enabling unauthenticated remote command execution. DIBs must verify API authentication controls and patch legacy SolarWinds instances, as this flaw was actively exploited in the wild to compromise networks.
Shame score — A critical authentication bypass in a widely deployed monitoring platform was actively exploited in the wild, causing massive network compromises and severe reputational damage.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.
"SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands."