PT-2021-17897 · Solarwinds · Solarwinds Orion Platform

Published

2021-07-27

·

Updated

2022-07-12

·

CVE-2021-28674

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SolarWinds Orion Platform versions prior to 2020.2.5 HF1
Description: The node management page in SolarWinds Orion Platform allows an attacker to create or delete a node outside of the attacker's perimeter via an account with write permissions. This occurs because node IDs are predictable and the access control on "Services/NodeManagement.asmx/DeleteObjNow" is incorrect. To exploit this, an attacker must be authenticated and must have node management rights associated with at least one valid group on the platform.
Recommendations: For versions prior to 2020.2.5 HF1, update to version 2020.2.5 HF1 or later to resolve the issue. As a temporary workaround, consider restricting access to the "Services/NodeManagement.asmx/DeleteObjNow" endpoint and limiting node management rights to only necessary groups and users. Additionally, ensure that all users with node management rights are properly authenticated and authorized.

Fix

Incorrect Authorization

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28674

Affected Products

Solarwinds Orion Platform