Show filters
50 Total Results
Displaying 1-10 of 50
Sort by:
Attacker Value
Very High
CVE-2020-10148 SolarWinds Orion API authentication bypass and RCE
Disclosure Date: December 29, 2020 (last updated February 22, 2025)
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
17
Attacker Value
Very High
SolarWinds Orion Platform Unauthenticated RCE (CVE-2021-25274)
Disclosure Date: February 03, 2021 (last updated November 28, 2024)
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem.
4
Attacker Value
Low
CVE-2022-38108
Disclosure Date: October 19, 2022 (last updated October 08, 2023)
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
1
Attacker Value
Unknown
CVE-2022-47505
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.
1
Attacker Value
Unknown
CVE-2022-47509
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.
1
Attacker Value
Unknown
SolarWinds Orion Platform Reverse Tabnabbing and Open Redirect — CVE-2021-3109
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context of an administrator account.
1
Attacker Value
Unknown
SolarWinds Orion Platform Stored XSS in Customize view —CVE-2020-35856
Disclosure Date: March 26, 2021 (last updated November 28, 2024)
SolarWinds Orion Platform before 2020.2.5 allows stored XSS attacks by an administrator on the Customize View page.
1
Attacker Value
Unknown
CVE-2021-25275
Disclosure Date: February 03, 2021 (last updated November 28, 2024)
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database.
1
Attacker Value
Unknown
CVE-2023-23845
Disclosure Date: September 13, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
0
Attacker Value
Unknown
CVE-2023-23840
Disclosure Date: September 13, 2023 (last updated October 08, 2023)
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
0