PT-2021-19356 · Solarwinds · Solarwinds Orion Job Scheduler

Harrison Neal

·

Published

2021-05-21

·

Updated

2021-06-03

·

CVE-2021-31475

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SolarWinds Orion Job Scheduler version 2020.2.1 HF 2
Description This issue allows remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this issue. The flaw exists within the JobRouterService WCF service due to its configuration, which allows a critical resource to be accessed by unprivileged users. An attacker can leverage this to execute code in the context of an administrator.
Recommendations For SolarWinds Orion Job Scheduler version 2020.2.1 HF 2, consider disabling the JobRouterService WCF service until a patch is available to prevent exploitation. Restrict access to the critical resource accessed by the WCF service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31475
ZDI-21-605

Affected Products

Solarwinds Orion Job Scheduler