VulnerabilityModified
CVE-2021-35244
An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
HIGH 7.2EPSS 5.77%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.77% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- solarwinds/orion platform
- Source
- psirt@solarwinds.com
References
- https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/core-secure-configuration.htmVendor Advisory
- https://support.solarwinds.com/SuccessCenter/s/article/Orion-Platform-2020-2-6-Hotfix-3?language=en_USRelease Notes, Vendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35242Not Applicable, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-375/Third Party Advisory, VDB Entry
- https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/core-secure-configuration.htmVendor Advisory
- https://support.solarwinds.com/SuccessCenter/s/article/Orion-Platform-2020-2-6-Hotfix-3?language=en_USRelease Notes, Vendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35242Not Applicable, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-375/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.