3 ms·
Could have been CVE-2020-7984: https://nvd.nist.gov/vuln/detail/CVE-2020-7984 https://nvd.nist.gov/vuln/detail/CVE-2020-7984 >SolarWinds N-central before 12.1
by resfirestar 6y ago
Could have been CVE-2020-7984: https://nvd.nist.gov/vuln/detail/CVE-2020-7984 https://nvd.nist.gov/vuln/detail/CVE-2020-7984
>SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information
- res0nat0r 6y agoNot knowing anything about this, this could be a good guess. Folks likely jumping the gun blaming a MS vuln above, when the real breach was via SolarWinds and then they were able to spoof/takeover some Active Directory server inside the network or something such thus gaining access to MS 365 emails etc.
- technion 6y agoThe articles are referring to Solarwinds Orion, which is a different product to N-central. I personally found and reported the unpublished CVE-2019-10690 in N-Central, but that was only local privesc.
- res0nat0r 6y agoMore info on the attack here: https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html https://www.fireeye.com/blog/threat-research/2020/12/evasive... > They gained access to victims via trojanized updates to SolarWind’s Orion IT monitoring and management software. This campaign may have begun as early as Spring 2020 and is currently ongoing. Post compromise activity following this supply chain compromise has included lateral movement and data theft. The campaign is the work of a highly skilled actor and the operation was conducted with significant operational security.