PT-2020-13167 · Solarwinds · Solarwinds Msp Pme Cache Service
Jens Regel
·
Published
2020-05-07
·
Updated
2020-05-15
·
CVE-2020-12608
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SolarWinds MSP PME (Patch Management Engine) Cache Service versions prior to 1.1.15
Description
An issue was discovered in the SolarWinds MSP PME Cache Service, where there are insecure file permissions for the directory containing the CacheService.xml configuration file. This can lead to code execution by changing the
SISServerURL parameter in the CacheService.xml file.Recommendations
For versions prior to 1.1.15, update to version 1.1.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the %PROGRAMDATA%SolarWinds MSPSolarWinds.MSP.CacheServiceconfig directory to prevent unauthorized changes to the CacheService.xml file.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Msp Pme Cache Service