Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hashed Credential Exposure Vulnerability
Vulnerability Description
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
不充分的加密强度
Vulnerability Title
SolarWinds Hybrid Cloud Observability 加密问题漏洞
Vulnerability Description
SolarWinds Hybrid Cloud Observability是美国SolarWinds公司的通过提高可见性、智能和生产力来帮助组织确保可用性并减少跨本地和多云环境的修复时间。 SolarWinds Hybrid Cloud Observability 2020.2.5版本及之前版本存在安全漏洞,该漏洞源于产品中的实体配置错误,并将密码字段暴露给Solarwinds Information Service(SWIS)。
CVSS Information
N/A
Vulnerability Type
N/A