VulnerabilityModified
CVE-2021-32076
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2.
MEDIUM 5.3EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- solarwinds/web help desk
- Source
- psirt@solarwinds.com
References
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/208278Third Party Advisory, VDB Entry
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-32076Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.