CVE-2021-35218
Last modified
CVE-2021-35218 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server. EPSS estimates a 76.41% chance of exploitation in the next 30 days.
Description
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Solarwinds | Orion Platform | < 2020.2.6 |
References
- https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.htmNot Applicable, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1248/Third Party Advisory, VDB Entry
- https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.htmNot Applicable, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1248/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-35218?
How severe is CVE-2021-35218?
How do I fix CVE-2021-35218?
Are you affected by CVE-2021-35218?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
