CVE-2020-10148
SolarWinds Orion Platform
Published 29 Dec 2020 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
References
- kb.cert.org/vuls/id/843464 · Third Party Advisory, US Government Resource
- www.solarwinds.com/securityadvisory · Vendor Advisory
- www.kb.cert.org/vuls/id/843464 · Third Party Advisory, US Government Resource
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-10148 · US Government Resource