Critical severity9.8CISA KEVNVD Advisory· Published Dec 29, 2020· Updated Jun 17, 2026
CVE-2020-10148
CVE-2020-10148
Description
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:solarwinds:orion_platform:2019.4:hotfix5:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:solarwinds:orion_platform:2019.4:hotfix5:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2.1:hotfix1:*:*:*:*:*:*
- cpe:2.3:a:solarwinds:orion_platform:2020.2:-:*:*:*:*:*:*
- (no CPE)range: 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1
- (no CPE)range: 2019.4 HF 5
- Range: 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1
Patches
Vulnerability mechanics
References
4- kb.cert.org/vuls/id/843464nvdThird Party AdvisoryUS Government Resource
- www.kb.cert.org/vuls/id/843464nvdThird Party AdvisoryUS Government Resource
- www.solarwinds.com/securityadvisorynvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.