An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwarding with a temporary key pair) to access network services on the 127.0.0.1 interface, even though this feature was only intended for user-to-agent communication.
References
Link | Resource |
---|---|
https://ernw.de/en/publications.html | Third Party Advisory |
https://support.solarwinds.com/SuccessCenter/s/ | Vendor Advisory |
https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/ | Third Party Advisory |
Configurations
Information
Published : 2020-12-16 06:15
Updated : 2020-12-21 08:20
NVD link : CVE-2020-25619
Mitre link : CVE-2020-25619
JSON object : View
CWE
Products Affected
solarwinds
- n-central