CVE-2021-35220: EmailWebPage Command Injection RCE
Published Aug 31, 2021
·Updated
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
Affected Software
1 affected component
SolarWinds Orion Platform<2020.2.6
Remediation
Information
SolarWinds recommends installing 2020.2.6 Hotfix 1 for the Orion Platform as soon as it becomes available. All customers should implement all the recommendations from the Orion Secure Configuration Guide.
Event History
Aug 31, 2021
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-35220?
CVE-2021-35220 is a Command Injection vulnerability in the EmailWebPage API that can lead to Remote Code Execution (RCE) from the Alerts Settings page.
2
How severe is CVE-2021-35220?
CVE-2021-35220 has a severity rating of 7.2 (high).
3
What software is affected by CVE-2021-35220?
The SolarWinds Orion Platform up to version 2020.2.6 is affected by CVE-2021-35220.
4
How can I mitigate the CVE-2021-35220 vulnerability?
You can mitigate the CVE-2021-35220 vulnerability by applying the hotfix provided by SolarWinds.
5
Where can I find more information about CVE-2021-35220?
You can find more information about CVE-2021-35220 in the release notes and support articles provided by SolarWinds.