Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmch-r6fm-gmwh

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.6

Описание

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.

EPSS

Процентиль: 0%
0.00007
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 5.6
nvd
6 месяцев назад

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.

CVSS3: 5.6
fstec
6 месяцев назад

Уязвимость программного обеспечения для мониторинга производительности SolarWinds Database Performance Analyzer (DPA), связанная с использованием предустановленных учетных данных, позволяющая нарушителю выполнить атаку «человек посередине» (MITM)

EPSS

Процентиль: 0%
0.00007
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-798