CVE-2021-35213: SolarWinds Orion Platform NCM SCM IPAM SaveUserSetting Improper Access Control Privilege Escalation Vulnerability
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication is required to exploit the vulnerability.
Other sources
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Orion Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper control of access to this endpoint. An attacker can leverage this vulnerability to escalate privileges from Guest to Administrator.
— ZDI
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35213?
CVE-2021-35213 is a vulnerability that allows remote attackers to escalate privileges on affected installations of SolarWinds Orion Platform.
How severe is CVE-2021-35213?
The severity of CVE-2021-35213 is critical with a CVSS score of 8.8.
Which software is affected by CVE-2021-35213?
The SolarWinds Orion Platform versions up to 2020.2.5 are affected by CVE-2021-35213.
What is the specific flaw in CVE-2021-35213?
The specific flaw in CVE-2021-35213 exists within the SaveUserSetting endpoint.
Is authentication required to exploit CVE-2021-35213?
Yes, authentication is required to exploit CVE-2021-35213.
How can I fix CVE-2021-35213?
To fix CVE-2021-35213, update your SolarWinds Orion Platform installation to version 2020.2.6 or later.