PT-2020-5339 · Solarwinds+1 · Solarwinds Database Performance Analyzer+1
Published
2020-08-11
·
Updated
2021-04-23
·
CVE-2020-25758
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DSR-250 version 3.17
SolarWinds Database Performance Analyzer (DPA) (affected versions not specified)
Description
An issue with insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading, which are executed as root. Additionally, a vulnerability in SolarWinds Database Performance Analyzer (DPA) is related to the failure to protect the web page structure, which could allow a remote attacker to perform a cross-site scripting attack.
Recommendations
For D-Link DSR-250 version 3.17, consider disabling the ability to upload saved configurations until a patch is available.
For SolarWinds Database Performance Analyzer (DPA), restrict access to the web interface to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Dsr-250
Solarwinds Database Performance Analyzer