7.8
CVSSv3

CVE-2020-12608

Published: 07/05/2020 Updated: 15/05/2020
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in SolarWinds MSP PME (Patch Management Engine) Cache Service prior to 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds managed service provider patch management engine

Exploits

SolarWinds MSP PME Cache Service versions prior to 1115 suffer from insecure file permission and code execution vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> SolarWinds MSP PME Cache Service - Insecure File Permissions / Code Execution <!--X-Subject-Header-End--> <!--X-Head-o ...