SecPod

Learn Search

Search across all Learn content

← Back to Security Research
SolarWinds Releases Updates to Address Vulnerability Exploited by SUPERNOVA Malware

SolarWinds Releases Updates to Address Vulnerability Exploited by SUPERNOVA Malware

SolarWinds has released an advisory on 27th December 2020 to address the vulnerability being exploited by SUPERNOVA malware. The vulnerability resides in the SolarWinds Orion API, making it vulnerable to an authentication bypass that can further lead to remote code execution. The vulnerability has b...

Dec 27, 2020By Ashish Bisht2 min read

SolarWinds has released an advisory on 27th December 2020 to address the vulnerability being exploited by SUPERNOVA malware. The vulnerability resides in the SolarWinds Orion API, making it vulnerable to an authentication bypass that can further lead to remote code execution. The vulnerability has been assigned as CVE-2020-10148. This can be used to deploy SUPERNOVA malware on the target environment. Hence, we require a vulnerability management tool to detect vulnerabilities.

Supernova Malware (CVE-2020-10148) details

Uses the SolarWinds Orion API to interface with all SolarWinds Orion Platform products. API authentication can bypass by including specific parameters in the Request.PathInfo portion of the URI request, which could allow an attacker to execute unauthenticated API commands. Moreover, if an attacker appends a PathInfoparameter of WebResource.adx, ScriptResource.adx, i18n.ashx, or Skipi18n to a request to a SolarWinds Orion server, SolarWinds may set the Skip Authorization flag, which then allows the API request process without requiring authentication. However, a patch management solution is essential here.

SUPERNOVA

SUPERNOVA is written in .NET and specifically made for usage on SolarWinds Orion servers. However, it deploys as a DLL module. Moreover, it consists of two components – one being an unsigned webshell.dll and the other for exploiting the vulnerability present in the Orion platform to enable the deployment of malware.

Impact of Supernova Malware

In addition, the vulnerability could allow remote attackers to bypass authentication and execute remote code, which would result in a compromise of the SolarWinds instance.

Affected platforms

The vulnerability resides in the Orion API. Hence it affects several products. These include Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed or with 2020.2 HF 1 including:
Application Centric Monitor
Database Performance Analyzer Integration Module
Enterprise Operations Console
High Availability
IP Address Manager
Log Analyzer
Network Automation Manager
Network Configuration Manager
Network Operations Manager
User Device Tracker
Network Performance Monitor
NetFlow Traffic Analyzer
Server & Application Monitor
Server Configuration Monitor
Storage Resource Monitor
Virtualization Manager
VoIP & Network Quality Manager
Web Performance Monitor (WPM)

Solution

Solarwinds has issued patches for fixing the vulnerability. SanerNow detects the vulnerability (CVE-2020-10148).

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026

SolarWinds Releases Updates to Address Vulnerability Exploited by SUPE | SecPod