ZeroHour

CVE-2020-10148

KEVlarge

Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)

CISA: SolarWinds Orion Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
92%p100
Published
()
KEV added
AI analysis

The SolarWinds Orion API contains a critical authentication bypass (CWE-288/CWE-306, CVSS 9.8) that allows a remote, unauthenticated attacker to execute API commands on the Orion Platform. It is triggered by specially crafted requests to the Orion API that reach endpoints with authorization skipped, requiring no privileges or user interaction. By issuing these API commands, an attacker can take control of the SolarWinds instance; in observed intrusions, the flaw was used to install the SUPERNOVA webshell on Orion servers. Any organization running Orion Platform 2019.4 HF 5, 2020.2 with no hotfix installed, or 2020.2 HF 1 is affected. Exploitation is in the wild: the flaw is listed in CISA's KEV (added 2021-11-03), has been linked to the China-nexus actor DEV-0322 per public reporting, and EPSS assigns it a 92% probability of exploitation within 30 days.

What to do: Apply the Orion Platform updates/hotfixes per SolarWinds' instructions and move all installations off the affected builds (2019.4 HF 5, 2020.2 without hotfix, 2020.2 HF 1). Until patched, restrict access to the Orion web console and API to trusted networks only. Hunt for compromise by checking for the SUPERNOVA webshell in the Orion web root and reviewing API logs for unauthenticated API command execution.

Affected
SolarWinds Orion Platform2019.4 HF 5; 2020.2 with no hotfix installed; 2020.2 HF 1
Estimated exposure
largetens of thousands of Orion deployments (roughly 25,000-33,000 customer sites) — SolarWinds publicly reported about 33,000 customers using Orion products at the time this flaw was disclosed, and the affected builds (2019.4 HF 5 and 2020.2) were the most widely installed Orion versions, so the order of magnitude is tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

CISA Known Exploited Vulnerability
Affected
SolarWinds Orion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
solarwinds
Products
orion platform
Weakness
CWE-288, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news