CVE-2021-31475: SolarWinds Orion Job Scheduler JobRouterService Improper Authorization Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authentication is required to exploit this vulnerability. The specific flaw exists within the JobRouterService WCF service. The issue is due to the WCF service configuration, which allows a critical resource to be accessed by unprivileged users. An attacker can leverage this vulnerability to execute code in the context of an administrator. Was ZDI-CAN-12007.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler. Authentication is required to exploit this vulnerability. The specific flaw exists within the JobRouterService WCF service. The issue is due to the WCF service configuration, which allows a critical resource to be accessed by unprivileged users. An attacker can leverage this vulnerability to execute code in the context of an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31475?
CVE-2021-31475 has been assigned a high severity rating due to the potential for remote code execution.
How do I fix CVE-2021-31475?
To remediate CVE-2021-31475, ensure that you update SolarWinds Orion Job Scheduler to version 2020.2.1 Hotfix 3 or later.
Who is affected by CVE-2021-31475?
CVE-2021-31475 affects installations of SolarWinds Orion Job Scheduler version 2020.2.1 Hotfix 2.
What type of attack is possible with CVE-2021-31475?
CVE-2021-31475 allows remote attackers to execute arbitrary code on affected systems after authentication.
Is authentication required to exploit CVE-2021-31475?
Yes, authentication is required to exploit CVE-2021-31475.