PT-2021-17897 · Solarwinds · Solarwinds Orion Platform
Published
2021-07-27
·
Updated
2022-07-12
·
CVE-2021-28674
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
SolarWinds Orion Platform versions prior to 2020.2.5 HF1
Description:
The node management page in SolarWinds Orion Platform allows an attacker to create or delete a node outside of the attacker's perimeter via an account with write permissions. This occurs because node IDs are predictable and the access control on "Services/NodeManagement.asmx/DeleteObjNow" is incorrect. To exploit this, an attacker must be authenticated and must have node management rights associated with at least one valid group on the platform.
Recommendations:
For versions prior to 2020.2.5 HF1, update to version 2020.2.5 HF1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Services/NodeManagement.asmx/DeleteObjNow" endpoint and limiting node management rights to only necessary groups and users. Additionally, ensure that all users with node management rights are properly authenticated and authorized.
Fix
Incorrect Authorization
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solarwinds Orion Platform