First published: Thu Oct 21 2021(Updated: )
Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Network Performance Monitor | <=2020.2.6 | |
SolarWinds Network Performance Monitor | =2020.2.6-hotfix1 |
SolarWinds recommends upgrading to the latest version of Network Performance Monitor 2020.2.6 Hotfix 2 as soon as it becomes available. All customers should review and implement all of the recommendations from the Orion Secure Configuration Guide
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-35225.
The severity of CVE-2021-35225 is medium, with a severity value of 6.4.
The affected software for CVE-2021-35225 is SolarWinds Network Performance Monitor version up to 2020.2.6-hotfix1.
An authenticated user in a MSP environment with CVE-2021-35225 can view and browse all NetPath Services from all the MSP's customers.
CVE-2021-35225 can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
To fix CVE-2021-35225, it is recommended to apply the necessary hotfixes provided by SolarWinds and perform a secure configuration of the Orion Platform.