CVE-2021-35212: SolarWinds Orion Network Performance Monitor DisableNOCView SQL Injection Privilege Escalation Vulnerability
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.
Other sources
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Orion Network Performance Monitor. Authentication is required to exploit this vulnerability. The specific flaw exists within the DisableNOCView method. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator.
— ZDI
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35212?
CVE-2021-35212 is a vulnerability that allows remote attackers to escalate privileges on affected installations of SolarWinds Orion Network Performance Monitor.
How severe is CVE-2021-35212?
CVE-2021-35212 has a severity rating of 8.8 (critical).
How does CVE-2021-35212 work?
CVE-2021-35212 exploits a flaw within the DisableNOCView method in SolarWinds Orion Network Performance Monitor, which results in the lack of proper input validation and allows for SQL injection and privilege escalation.
What versions of SolarWinds Orion Platform are affected by CVE-2021-35212?
CVE-2021-35212 affects the 2019.2, 2019.4, 2020.2.1, 2020.2.4, and 2020.2.5 versions of SolarWinds Orion Platform.
How can I fix CVE-2021-35212?
To fix CVE-2021-35212, update SolarWinds Orion Platform to a non-vulnerable version and follow the secure configuration guidelines provided by SolarWinds.