CVE-2021-28674
Last modified
CVE-2021-28674 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the access control on Services/NodeManagement.asmx/DeleteObjNow is incorrect. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the access control on Services/NodeManagement.asmx/DeleteObjNow is incorrect. To exploit this, an attacker must be authenticated and must have node management rights associated with at least one valid group on the platform.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Orion Platform | <= 2020.2.5 |
References
- https://pastebin.com/zFUd2cCjThird Party Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-28674Patch, Vendor Advisory
- https://pastebin.com/zFUd2cCjThird Party Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-28674Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-28674?
How severe is CVE-2021-28674?
How do I fix CVE-2021-28674?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-28668Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 b…9.8
- CVE-2021-28669Xerox AltaLink B80xx before 103.008.020.23120, C8030/C8035 b…7.5
- CVE-2021-28670Xerox AltaLink B8045/B8090 before 103.008.030.32000, C8030/C…9.1
- CVE-2021-28671Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), Wor…9.8
- CVE-2021-28672Xerox Phaser 6510 before 64.65.51 and 64.59.11 (Bridge), Wor…9.8
- CVE-2021-28673Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), Wor…9.8
- CVE-2021-28675An issue was discovered in Pillow before 8.2.0. PSDImagePlug…5.5
- CVE-2021-28676An issue was discovered in Pillow before 8.2.0. For FLI data…7.5
- CVE-2021-28677An issue was discovered in Pillow before 8.2.0. For EPS data…7.5
- CVE-2021-28678An issue was discovered in Pillow before 8.2.0. For BLP data…5.5
- CVE-2021-28680The devise_masquerade gem before 1.3 allows certain attacks …8.1
- CVE-2021-28681Pion WebRTC before 3.0.15 didn't properly tear down the DTLS…5.3
Are you affected by CVE-2021-28674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
