PT-2015-6984 · Solarwinds · Solarwinds N-Central

Gary Blosser

·

Publicado

2015-07-21

·

Atualizado

2016-11-28

·

CVE-2015-5610

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SolarWinds N-Able N-Central versions prior to 9.5.1.4514
Description The issue allows remote authenticated users to obtain the cleartext domain-administrator password. This is possible because the RSM service uses the same password decryption key across different customers' installations. An attacker can locate the encrypted password within HTML source code and then use knowledge of this key from another installation to obtain the password.
Recommendations For versions prior to 9.5.1.4514, update to version 9.5.1.4514 or later to resolve the issue. As a temporary workaround, consider restricting access to the RSM service to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-5610

Produtos afetados

Solarwinds N-Central