SB2021110223 - Privilege escalation in SolarWinds Network Performance Monitor
Published: November 2, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-35225)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to each authenticated Orion user in the MSP (Managed Service Provider) environment can view and browse all NetPath Services from all MSP's customers. A remote authenticated attacker can have a limited insight into other customers' infrastructure and cause potential data cross-contamination.
Remediation
Install update from vendor's website.