CVE-2021-35214: Session Management Vulnerability
The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user session upon password or email address change. When running multiple active sessions in separate browser windows, it was observed a password or email address change could be changed without terminating the user session. This issue has been resolved on September 13, 2021.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35214?
The severity of CVE-2021-35214 is considered medium due to the potential for unauthorized access with active sessions.
How do I fix CVE-2021-35214?
To fix CVE-2021-35214, ensure that users update to a version of SolarWinds Pingdom released after September 13, 2021.
What type of vulnerability is CVE-2021-35214?
CVE-2021-35214 is an authentication vulnerability related to session management.
Who is affected by CVE-2021-35214?
Users of SolarWinds Pingdom prior to version 13.09.2021 are affected by CVE-2021-35214.
Can CVE-2021-35214 lead to account takeover?
Yes, CVE-2021-35214 can potentially lead to account takeover if an active session is exploited.