CVE-2021-35226: Hashed Credential Exposure Vulnerability
Published Oct 10, 2022
·Updated
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.
Affected Software
1 affected component
SolarWinds Network Configuration Manager<=2020.2.5
Remediation
Information
SolarWinds recommends customers upgrade to the latest version once it becomes generally available.
Event History
Oct 10, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-35226.
2
What is the title of this vulnerability?
The title of this vulnerability is 'An entity in Network Configuration Manager product is misconfigured and exposing password field to SWIS'.
3
What is the severity of CVE-2021-35226?
The severity of CVE-2021-35226 is medium (6.5).
4
Which software is affected by CVE-2021-35226?
The Solarwinds Network Configuration Manager (version 2020.2.5) is affected by CVE-2021-35226.
5
How can this vulnerability be fixed?
To fix CVE-2021-35226, ensure that the entity in Network Configuration Manager product is properly configured and not exposing the password field to SWIS.