CVE-2021-35218
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server
Affected (1)
Products: Solarwinds: Orion Platform
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2020.2.6 |
References (6)
Source: psirt@solarwinds.com
Not ApplicableVendor Advisory
Source: psirt@solarwinds.com
Vendor Advisory
Source: psirt@solarwinds.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.