ATT&CKReferencesCarnegie Mellon University Supernova Dec 2020

Carnegie Mellon University Supernova Dec 2020

Carnegie Mellon University. (2020, December 26). SolarWinds Orion API authentication bypass allows remote command execution. Retrieved February 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

TechniqueUsed byProcedure example
T1203
Exploitation for Client Execution
MalwareSUPERNOVA

SUPERNOVA was installed via exploitation of a SolarWinds Orion API authentication bypass vulnerability (CVE-2020-10148).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.