SB2021110223 - Privilege escalation in SolarWinds Network Performance Monitor 



SB2021110223 - Privilege escalation in SolarWinds Network Performance Monitor

Published: November 2, 2021

Security Bulletin ID SB2021110223
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-35225)

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to each authenticated Orion user in the MSP (Managed Service Provider) environment can view and browse all NetPath Services from all MSP's customers. A remote authenticated attacker can have a limited insight into other customers' infrastructure and cause potential data cross-contamination.


Remediation

Install update from vendor's website.