PT-2022-5000 · Solarwinds · Network Configuration Manager

Published

2022-10-10

·

Updated

2023-08-03

·

CVE-2021-35226

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Network Configuration Manager (affected versions not specified)
Description The issue is related to a misconfigured entity in the Network Configuration Manager product, which exposes a password field to the Solarwinds Information Service (SWIS). The exposed credentials are encrypted and can only be accessed with authenticated access and an NCM role. This could potentially allow a remote attacker to disclose user credentials through command injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

BDU:2022-06212
CVE-2021-35226

Affected Products

Network Configuration Manager