Known vulnerabilities in Orion Network Performance Monitor 2020.2 Hotfix 1
Vendor:
SolarWinds
Software:
Orion Network Performance Monitor
Version:
2020.2 Hotfix 1
Software CPE:
cpe:2.3:a:solarwinds:orion_network_performance_monitor:*:*:*:*:*:*:*:*
Website:
https://www.solarwinds.com/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.4
Vulnerabilities by Severity
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU49924 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-27871 |
CWE-22 | Medium | - | 22.01.2021 |
SB2021012201 |
||
| #VU49923 - Exposure of sensitive information to an unauthorized actor CVE-2020-27870 |
CWE-200 | Medium | - | 22.01.2021 |
SB2021012201 |
||
| #VU49922 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2020-27869 |
CWE-89 | Medium | - | 22.01.2021 |
SB2021012201 |
||
| #VU49921 - Improper input validation CVE-2020-14005 |
CWE-20 | Medium | - | 22.01.2021 |
SB2021012201 |