PT-2021-16496 · Solarwinds · Solarwinds Orion Platform

Published

2021-02-03

·

Updated

2021-02-08

·

CVE-2021-25275

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SolarWinds Orion Platform versions prior to 2020.2.4
Description: The issue allows any user with access to the filesystem to read database login details, including the login name and its associated password, from a file. These credentials can then be used to gain database owner access to the SWNetPerfMon.DB database, providing access to the data collected by SolarWinds applications. This access can further lead to admin access to the applications by modifying authentication data stored in the Accounts table of the database.
Recommendations: For versions prior to 2020.2.4, update to version 2020.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the file containing database credentials to prevent unauthorized users from reading the login details. Additionally, restrict access to the SWNetPerfMon.DB database and the Accounts table to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25275

Affected Products

Solarwinds Orion Platform