CVE-2021-35246: Unprotected Transport of Credentials (HSTS) Vulnerability
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35246?
CVE-2021-35246 is a vulnerability in the Solarwinds Engineer's Toolset application that allows attackers to bypass SSL/TLS encryption and launch attacks against users.
How does CVE-2021-35246 affect the Solarwinds Engineer's Toolset?
CVE-2021-35246 allows users to connect to the application over unencrypted connections, which can be exploited by attackers to modify network traffic and launch attacks.
What is the severity of CVE-2021-35246?
CVE-2021-35246 has a severity rating of medium with a CVSS score of 5.3.
How can I fix CVE-2021-35246 in Solarwinds Engineer's Toolset?
To fix CVE-2021-35246, it is recommended to update to the latest version of Solarwinds Engineer's Toolset that includes a patch for the vulnerability.
Where can I find more information about CVE-2021-35246?
More information about CVE-2021-35246 can be found on the MITRE CVE database, Solarwinds documentation, and Solarwinds security advisories.