CVE-2020-12608 | SolarWinds MSP PME Cache Service up to 1.1.14 Advanced Monitoring Agent SISServerURL default permission (EDB-48448)
A vulnerability was found in SolarWinds MSP PME Cache Service up to 1.1.14. It has been declared as critical. This vulnerability affects unknown code of the file MSP\SolarWinds.MSP.CacheService\config\ of the component Advanced Monitoring Agent. The manipulation of the argument SISServerURL as part of Parameter leads to incorrect default permissions.
This vulnerability was named CVE-2020-12608. Attacking locally is a requirement. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.