SecPod

Learn Search

Search across all Learn content

← Back to Security Research
SolarWinds Releases Updates to Address Vulnerability Exploited by SUPERNOVA Malware

SolarWinds Releases Updates to Address Vulnerability Exploited by SUPERNOVA Malware

SolarWinds has released an advisory on 27th December 2020 to address the vulnerability being exploited by SUPERNOVA malware. The vulnerability resides in the SolarWinds Orion API, making it vulnerable to an authentication bypass that can further lead to remote code execution. The vulnerability has b...

Dec 27, 2020By Ashish Bisht2 min read

SolarWinds has released an advisory on 27th December 2020 to address the vulnerability being exploited by SUPERNOVA malware. The vulnerability resides in the SolarWinds Orion API, making it vulnerable to an authentication bypass that can further lead to remote code execution. The vulnerability has been assigned as CVE-2020-10148. This can be used to deploy SUPERNOVA malware on the target environment. Hence, we require a vulnerability management tool to detect vulnerabilities.

Supernova Malware (CVE-2020-10148) details

Uses the SolarWinds Orion API to interface with all SolarWinds Orion Platform products. API authentication can bypass by including specific parameters in the Request.PathInfo portion of the URI request, which could allow an attacker to execute unauthenticated API commands. Moreover, if an attacker appends a PathInfoparameter of WebResource.adx, ScriptResource.adx, i18n.ashx, or Skipi18n to a request to a SolarWinds Orion server, SolarWinds may set the Skip Authorization flag, which then allows the API request process without requiring authentication. However, a patch management solution is essential here.

SUPERNOVA

SUPERNOVA is written in .NET and specifically made for usage on SolarWinds Orion servers. However, it deploys as a DLL module. Moreover, it consists of two components – one being an unsigned webshell.dll and the other for exploiting the vulnerability present in the Orion platform to enable the deployment of malware.

Impact of Supernova Malware

In addition, the vulnerability could allow remote attackers to bypass authentication and execute remote code, which would result in a compromise of the SolarWinds instance.

Affected platforms

The vulnerability resides in the Orion API. Hence it affects several products. These include Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed or with 2020.2 HF 1 including:
Application Centric Monitor
Database Performance Analyzer Integration Module
Enterprise Operations Console
High Availability
IP Address Manager
Log Analyzer
Network Automation Manager
Network Configuration Manager
Network Operations Manager
User Device Tracker
Network Performance Monitor
NetFlow Traffic Analyzer
Server & Application Monitor
Server Configuration Monitor
Storage Resource Monitor
Virtualization Manager
VoIP & Network Quality Manager
Web Performance Monitor (WPM)

Solution

Solarwinds has issued patches for fixing the vulnerability. SanerNow detects the vulnerability (CVE-2020-10148).

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026