CVE-2021-35221: ImportAlert Improper Access Control Tampering Vulnerability
Published Aug 31, 2021
·Updated
Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
Affected Software
2 affected components
SolarWinds Orion Platform<2020.2.6
Microsoft Windows
Remediation
Information
SolarWinds recommends installing 2020.2.6 Hotfix 1 for the Orion Platform as soon as it becomes available. All customers should implement all the recommendations from the Orion Secure Configuration Guide.
Event History
Aug 31, 2021
CVE Published
via MITRE·12:13 PM
Data Sourced
via MITRE·12:13 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-35221?
CVE-2021-35221 is an Improper Access Control Tampering Vulnerability that can lead to Remote Code Execution (RCE) from the Alerts Settings page.
2
How severe is CVE-2021-35221?
CVE-2021-35221 has a severity rating of 8.1 (High).
3
What software is affected by CVE-2021-35221?
The SolarWinds Orion Platform up to version 2020.2.6 is affected by CVE-2021-35221.
4
How can I mitigate CVE-2021-35221?
You can mitigate CVE-2021-35221 by applying the hotfix provided by SolarWinds and following their secure configuration guidelines.
5
Where can I find more information about CVE-2021-35221?
You can find more information about CVE-2021-35221 in the SolarWinds documentation and support articles.