5
CVSSv2

CVE-2020-7984

Published: 26/01/2020 Updated: 05/02/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SolarWinds N-central prior to 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote malicious users to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any aspects of the agent/appliance configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds n-central

Github Repositories

This application utilized the Self Registration feature to create a rogue agent that then dumps ApplianceConfiguration settings which may or may not contain information such as plain text passwords. This was reported to SolarWinds PSIRT on 10/10/2019 with very little feedback.

SolarWinds n-Central Dumpster Diver Description / Explanation FIXES/WORKAROUNDS have been released for more information: cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2020-7984 This application utilizes the nCentral agent dot net libraries to simulate the agent registration and pull the agent/appliance configuration settings This information can contain plain text active