First published: Wed Sep 01 2021(Updated: )
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Orion Platform | <=2020.2.5 | |
Customers are advised to update to Orion Platform 2020.2.6 once it becomes available,
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35215 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform.
The severity of CVE-2021-35215 is rated as high with a severity value of 8.8.
The CVE-2021-35215 vulnerability exists within the ActionPluginBaseView class and is a result of the lack of proper validation of untrusted data, allowing remote code execution.
To exploit CVE-2021-35215, an attacker would need to authenticate and send specially crafted data to the affected SolarWinds Orion Platform installation.
To fix CVE-2021-35215, it is recommended to update to SolarWinds Orion Platform version 2020.2.6 or higher, as it contains the necessary security patches.