CVE-2021-35225: Netpath Horizontal Privilege Escalation Vulnerability: NPM 2020.2.5
Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-35225.
What is the severity of CVE-2021-35225?
The severity of CVE-2021-35225 is medium, with a severity value of 6.4.
What is the affected software for CVE-2021-35225?
The affected software for CVE-2021-35225 is SolarWinds Network Performance Monitor version up to 2020.2.6-hotfix1.
What can an authenticated user do in a MSP environment with CVE-2021-35225?
An authenticated user in a MSP environment with CVE-2021-35225 can view and browse all NetPath Services from all the MSP's customers.
What is the potential risk of CVE-2021-35225?
CVE-2021-35225 can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination.
How can I fix CVE-2021-35225?
To fix CVE-2021-35225, it is recommended to apply the necessary hotfixes provided by SolarWinds and perform a secure configuration of the Orion Platform.