PT-2021-5712 · Solarwinds · Solarwinds Orion Platform

Fkadibs

·

Published

2021-12-20

·

Updated

2022-03-17

·

CVE-2021-35244

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SolarWinds Orion Platform (affected versions not specified)
Description The issue is related to the "Log alert to a file" action within action management in the SolarWinds Orion Platform, which allows any user with Orion alert management rights to write to any file. This can be exploited by an attacker to perform an unrestricted file upload, potentially leading to remote code execution. The vulnerability is associated with an unlimited upload of dangerous file types, which can enable a remote attacker to elevate their privileges or execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00154
CVE-2021-35244
ZDI-22-375

Affected Products

Solarwinds Orion Platform