VulnerabilityModified
CVE-2021-35216
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module.
HIGH 8.8EPSS 81.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 81.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 81.40% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- solarwinds/patch manager
- Source
- psirt@solarwinds.com
References
- https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.htmRelease Notes, Vendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35216Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1246/Third Party Advisory, VDB Entry
- https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.htmRelease Notes, Vendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35216Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1246/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.