Vulnerabilities > Solarwinds > N Central

DATE CVE VULNERABILITY TITLE RISK
2020-12-16 CVE-2020-25622 Cross-Site Request Forgery (CSRF) vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
network
low complexity
solarwinds CWE-352
8.8
2020-12-16 CVE-2020-25621 Missing Authentication for Critical Function vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
local
low complexity
solarwinds CWE-306
8.4
2020-12-16 CVE-2020-25620 Use of Hard-coded Credentials vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
local
low complexity
solarwinds CWE-798
7.8
2020-12-16 CVE-2020-25619 Unspecified vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
local
low complexity
solarwinds
4.4
2020-12-16 CVE-2020-25618 OS Command Injection vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
network
low complexity
solarwinds CWE-78
8.8
2020-12-16 CVE-2020-25617 Path Traversal vulnerability in Solarwinds N-Central 12.3.0.670
An issue was discovered in SolarWinds N-Central 12.3.0.670.
network
low complexity
solarwinds CWE-22
8.8
2020-10-19 CVE-2020-15910 Incorrect Permission Assignment for Critical Resource vulnerability in Solarwinds N-Central 12.3
SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly.
network
low complexity
solarwinds CWE-732
4.7
2020-10-19 CVE-2020-15909 Session Fixation vulnerability in Solarwinds N-Central
SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access.
network
low complexity
solarwinds CWE-384
8.8
2020-01-26 CVE-2020-7984 Cleartext Transmission of Sensitive Information vulnerability in Solarwinds N-Central 12.2
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information.
network
low complexity
solarwinds CWE-319
7.5