'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2020-10148: Solarwinds Orion Platform Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2020-10148
| Descripiton:
|
Solarwinds Orion Platform is a network failure and network performance management platform of Solarwinds, USA. The platform can provide real-time monitoring and analysis of network devices, and support custom web interfaces, a variety of user comments, and map throughout the network. SolarWinds Orion Platform exists for licensing vulnerabilities, which is from API authentication to bypass by containing specific parameters in the request. The PathInfo section requested by the URI, and an attacker can take advantage of this vulnerability to perform unauthenticated API commands. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.