Record summary

CVE-2020-12608 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBSolarWinds MSP PME Cache Service 1.1.14 - Insecure File PermissionsExploitDB exploitby Jens RegelNot analyzed1 file
ExploitDB

PoC details

References

4