Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmch-r6fm-gmwh

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.

EPSS

Процентиль: 9%
0.00189
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.6
nvd
12 месяцев назад

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.

CVSS3: 5.6
fstec
12 месяцев назад

Уязвимость программного обеспечения для мониторинга производительности SolarWinds Database Performance Analyzer (DPA), связанная с использованием предустановленных учетных данных, позволяющая нарушителю выполнить атаку «человек посередине» (MITM)

EPSS

Процентиль: 9%
0.00189
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-798