packetstormsecurity.com
http://packetstormsecurity.com/files/157591/SolarWinds-MSP-PME-Cache-Service-Insecure-File-Permissions-Code-Execution.html CVE-2020-12608
HIGH
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
Record summary
CVE-2020-12608 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by changing the CacheService.xml SISServerURL parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSolarWinds MSP PME Cache Service 1.1.14 - Insecure File PermissionsExploitDB exploitby Jens RegelNot analyzed1 file
References
420200508 SolarWinds MSP PME Cache Service - Insecure File Permissions / Code Executionmailing list
http://seclists.org/fulldisclosure/2020/May/23 github.com
https://github.com/jensregel/Advisories/tree/master/CVE-2020-12608 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-12608