CVE-2021-35217

high

Description

Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data.

References

https://www.zerodayinitiative.com/advisories/ZDI-21-1247/

https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35217

https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/orion_platform_2020-2-6_release_notes.htm

https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm

Details

Source: Mitre, NVD

Published: 2021-09-08

Updated: 2021-11-03

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.60058