Lucene search

K
cveZdiCVE-2020-27870
HistoryFeb 10, 2021 - 11:15 p.m.

CVE-2020-27870

2021-02-1023:15:12
CWE-22
zdi
web.nvd.nist.gov
42
8
cve-2020-27870
solarwinds
orion platform
vulnerability disclosure
information disclosure
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.019

Percentile

88.5%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw exists within ExportToPDF.aspx. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-11917.

Affected configurations

Nvd
Vulners
Node
solarwindsorion_platformMatch2020.2.1
VendorProductVersionCPE
solarwindsorion_platform2020.2.1cpe:2.3:a:solarwinds:orion_platform:2020.2.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Orion Platform",
    "vendor": "SolarWinds",
    "versions": [
      {
        "status": "affected",
        "version": "2020.2.1"
      }
    ]
  }
]

Social References

More

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.019

Percentile

88.5%

Related for CVE-2020-27870