CISA Known Exploited Vulnerability

CVE-2020-10148

SolarWinds · Orion

SolarWinds Orion Authentication Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-288
Ransomware Unknown

CISA description

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

Required action

Apply updates per vendor instructions.