SB2021110223 - Privilege escalation in SolarWinds Network Performance Monitor
Published: November 2, 2021
Security Bulletin ID
SB2021110223
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2021-35225)
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to each authenticated Orion user in the MSP (Managed Service Provider) environment can view and browse all NetPath Services from all MSP's customers. A remote authenticated attacker can have a limited insight into other customers' infrastructure and cause potential data cross-contamination.
Remediation
Install update from vendor's website.