PT-2021-19203 · Solarwinds · Solarwinds Dameware Mini Remote Control
Adriaan Schuitmaker
·
Published
2021-07-13
·
Updated
2021-07-15
·
CVE-2021-31217
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SolarWinds DameWare Mini Remote Control Server version 12.0.1.200
Description
The issue is related to insecure file permissions in the SolarWinds DameWare Mini Remote Control Server, which allows file deletion as SYSTEM.
Recommendations
For SolarWinds DameWare Mini Remote Control Server version 12.0.1.200, consider restricting file access permissions to prevent unauthorized deletion as a temporary workaround until a patch is available.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Dameware Mini Remote Control