PT-2018-13751 · Solarwinds · Solarwinds Sftp/Scp Server
Alex Craggs
·
Published
2018-12-05
·
Updated
2019-10-03
·
CVE-2018-16791
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SolarWinds SFTP/SCP Server versions prior to 2018-09-10
Description
The configuration file of the affected software is world readable and writable, storing user passwords insecurely. This allows an attacker to determine passwords for potentially privileged accounts and grants the ability to backdoor the server.
Recommendations
For versions prior to 2018-09-10, restrict access to the configuration file to prevent unauthorized modifications and reading of sensitive information. As a temporary workaround, consider implementing additional access controls to limit the potential impact of the insecure password storage.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Sftp/Scp Server