First published: Mon Dec 20 2021(Updated: )
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Orion Platform | <2020.2.6 | |
SolarWinds Orion Platform | =2020.2.6 | |
SolarWinds Orion Platform | =2020.2.6-hotfix1 | |
SolarWinds Orion Platform | =2020.2.6-hotfix2 | |
Microsoft Windows | ||
SolarWinds recommends customers upgrade to the latest version once it becomes generally available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35244 is a vulnerability that allows remote attackers to execute arbitrary code on SolarWinds Orion Platform.
Yes, authentication is required to exploit CVE-2021-35244.
CVE-2021-35244 has a severity value of 8.8 (high).
SolarWinds Orion Platform versions up to 2020.2.6 and hotfixes 2020.2.6-hotfix1 and 2020.2.6-hotfix2 are affected by CVE-2021-35244.
To fix CVE-2021-35244, apply the necessary patches and updates provided by SolarWinds.