N Central
Vendor:
First CVE: Jan 26, 2020 · Active for 6 years
9
Total CVEs
More Total CVEs than 88% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact N Central over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2020
6 years ago
Most Recent CVE
Dec 16, 2020
2,050 days ago
CVE Severity & Scoring
N Central9 CVEs
22%
78%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (33.3%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25618HIGH An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitr | Dec 16, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-15909HIGH SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against mult | Oct 19, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-25617HIGH An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administratio | Dec 16, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-25622HIGH An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. | Dec 16, 2020 | 8.8 | 25 | NO | NO |
CVE-2020-25621HIGH An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The | Dec 16, 2020 | 8.4 | 25 | NO | NO |
CVE-2020-25620HIGH An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] and [email protected]. Thes | Dec 16, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-7984HIGH SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain | Jan 26, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-25619MEDIUM An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH fea | Dec 16, 2020 | 4.4 | 17 | NO | NO |
CVE-2020-15910MEDIUM SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could | Oct 19, 2020 | 4.7 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For N Central
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.3.0.670 | 6 | 7.8 | 1.4% | 0 | 0 |