Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 5.8%
exploitation probability
5.8%top 7% of all CVEs
observed exploitation
nono source reports it
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
Affected products
SolarWinds · Orion PlatformReferences
https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/core-secure-configuration.htmhttps://support.solarwinds.com/SuccessCenter/s/article/Orion-Platform-2020-2-6-Hotfix-3?language=en_UShttps://www.solarwinds.com/trust-center/security-advisories/cve-2021-35242https://www.zerodayinitiative.com/advisories/ZDI-22-375/