CVE-2021-25274: Critical severity solarwinds orion platform vulnerability
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue in SolarWinds Orion Platform?
The vulnerability ID for this security issue in SolarWinds Orion Platform is CVE-2021-25274.
What is the severity of CVE-2021-25274?
The severity of CVE-2021-25274 is critical with a severity value of 9.8.
How does the Collector Service in SolarWinds Orion Platform before 2020.2.4 use MSMQ?
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue).
What is the impact of CVE-2021-25274?
CVE-2021-25274 allows remote unauthenticated clients to send messages to TCP port 1801 that the Collector Service will process.
How can the vulnerability CVE-2021-25274 be fixed?
To fix the vulnerability CVE-2021-25274, it is recommended to update to SolarWinds Orion Platform version 2020.2.4 or above.