Overview
SolarWinds N-Able N-Central is an agent-based enterprise support and management solution. N-Able N-Central contains several hard-coded encryption constants in the web interface that allow decryption of the password when combined.
Description
CWE-547: Use of Hard-coded, Security-relevant Constants N-Able N-Central's RSM service stores the N-Able domain administrator account password in an encrypted (AES128) format. According to the reporter, however, the encrypted password is accessible by any authenticated local or remote user from within from the RSM web page source. The credentials are also available in an encrypted format via local RSM configuration files accessible by any local user with rights to browse program files. The encryption keys as well as other parameters needed for decryption are hard-coded and may be extracted from the N-Able RSM software stored on the local users system. An attacker can use this information to decrypt and obtain the domain administrator password used by the N-Able software. |
Impact
According to the reporter, a remote attacker with domain user credentials or access to RSM files on an installed system can obtain domain administrator access. |
Solution
Apply an Update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.7 | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Temporal | 6.6 | E:POC/RL:U/RC:UR |
Environmental | 4.9 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Gary Blosser for reporting this vulnerability to us.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | None |
Date Public: | 2015-07-20 |
Date First Published: | 2015-07-20 |
Date Last Updated: | 2015-07-20 19:18 UTC |
Document Revision: | 45 |