S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2020-10148 Scanner

CVE-2020-10148 scanner - Authentication Bypass vulnerability in SolarWinds Orion

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-10148
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Orion Platformby SolarWinds
2019.4 HF 5
orion_platformby solarwinds
2019.4
orion_platformby solarwinds
2020.2.1
orion_platformby solarwinds
2020.2
Updated Aug 21, 2026View on NVD →
Detail

SolarWinds Orion is a powerful information technology management tool that enables network engineers and administrators to monitor and manage their network infrastructure, servers, applications, and more. This tool helps IT professionals to maintain the health and performance of their networks, detect issues, and fix them before they impact business operations. SolarWinds Orion is widely used by medium to large enterprises, government agencies, and managed service providers (MSPs) worldwide.

Recently, a critical vulnerability has been detected in the SolarWinds Orion API, identified by the code CVE-2020-10148. This vulnerability can allow malicious actors to bypass authentication and execute arbitrary API commands that can compromise the security of the entire SolarWinds instance. An attacker can exploit this vulnerability by sending specially crafted requests to the API, which may result in unauthorized access to sensitive resources, data theft, or malicious code execution on the affected systems.

If this vulnerability is successfully exploited, it can lead to significant damage to the affected systems. The attacker can gain access to confidential information, modify data, exfiltrate data, or deploy malware payloads, compromising the confidentiality, integrity, and availability of the network infrastructure and business-critical applications. This can cause significant financial losses, damage to reputation, and legal repercussions.

Thanks to the pro features of s4e.io, IT professionals can easily and quickly identify their digital assets' vulnerabilities. Our platform allows users to scan and detect vulnerabilities in their IT infrastructure and web applications, rate their severity level, and recommend actionable steps to remediate the risk. We pride ourselves on providing reliable and up-to-date cybersecurity solutions that help our customers stay protected against the latest cyber threats and attacks.

 

REFERENCES

Solution Advice

In order to protect against this vulnerability, SolarWinds has released several security updates and patches that should be implemented immediately. In addition, network administrators are advised to follow these precautions:

  • Keep SolarWinds Orion and its components up-to-date with the latest security patches and updates.
  • Implement strong access control policies and enable multi-factor authentication for all privileged accounts.
  • Restrict access to the SolarWinds Orion API to only authorized users and IPs.
  • Monitor SolarWinds Orion logs and network traffic for any suspicious activities or anomalies.
  • Conduct regular vulnerability assessments and penetration testing to identify and remediate any security weaknesses in the network infrastructure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.