vendor:
SolarWinds MSP PME Cache Service
by:
Jens Regel, Schneider & Wulf EDV-Beratung GmbH & Co. KG
7.8
CVSS
HIGH
Insecure File Permissions
276
CWE
Product Name: SolarWinds MSP PME Cache Service
Affected Version From: 1.1.14
Affected Version To: 1.1.14
Patch Exists: YES
Related CWE: CVE-2020-12608
CPE: solarwindsmsp:pme_cache_service:1.1.14
Platforms Tested:
2020
SolarWinds MSP PME Cache Service 1.1.14 – Insecure File Permissions
An error with insecure file permissions has occurred in the SolarWinds MSP Cache Service, which can lead to code execution. The CacheService.xml file in %PROGRAMDATA%SolarWinds MSPSolarWinds.MSP.CacheServiceconfig is writable by normal users, allowing them to change the SISServerURL parameter and control the location of updates.
Mitigation:
Upgrade to SolarWinds MSP PME version 1.1.15 or later.