Vulnerability Description
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Sftp\/Scp Server | <= 20180910 |
Related Weaknesses (CWE)
References
- https://seclists.org/fulldisclosure/2018/Dec/0Mailing ListThird Party Advisory
- https://seclists.org/fulldisclosure/2018/Dec/0Mailing ListThird Party Advisory
FAQ
What is CVE-2018-16791?
CVE-2018-16791 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords fo...
How severe is CVE-2018-16791?
CVE-2018-16791 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-16791?
Check the references section above for vendor advisories and patch information. Affected products include: Solarwinds Sftp\/Scp Server.