Описание
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.
Ссылки
- Release NotesVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
EPSS
5.6 Medium
CVSS3
6.4 Medium
CVSS3
Дефекты
Связанные уязвимости
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.
Уязвимость программного обеспечения для мониторинга производительности SolarWinds Database Performance Analyzer (DPA), связанная с использованием предустановленных учетных данных, позволяющая нарушителю выполнить атаку «человек посередине» (MITM)
EPSS
5.6 Medium
CVSS3
6.4 Medium
CVSS3