The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 17 Mar 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | CWE-306 |
Status: PUBLISHED
Assigner: certcc
Published: 2020-12-29T21:55:16.195Z
Updated: 2025-10-21T23:35:30.955Z
Reserved: 2020-03-05T00:00:00.000Z
Link: CVE-2020-10148
Updated: 2024-08-04T10:50:57.882Z
Status : Analyzed
Published: 2020-12-29T22:15:12.327
Modified: 2025-10-24T14:36:09.547
Link: CVE-2020-10148
No data.