Lucene search

K
cveSolarWindsCVE-2021-35215
HistorySep 01, 2021 - 3:15 p.m.

CVE-2021-35215

2021-09-0115:15:08
CWE-502
SolarWinds
web.nvd.nist.gov
84
cve-2021-35215
insecure deserialization
remote code execution
orion platform
authentication required
vulnerability

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.9

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

AI Score

9

Confidence

High

EPSS

0.121

Percentile

95.4%

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

Affected configurations

Nvd
Node
solarwindsorion_platformRange2020.2.5
VendorProductVersionCPE
solarwindsorion_platform*cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "platforms": [
      "Windows"
    ],
    "product": "Orion Platform",
    "vendor": "SolarWinds",
    "versions": [
      {
        "lessThan": "2020.2.6",
        "status": "affected",
        "version": "2020.2.5 and previous versions",
        "versionType": "custom"
      }
    ]
  }
]

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.9

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

AI Score

9

Confidence

High

EPSS

0.121

Percentile

95.4%