← back
CVE-2021-35248mediumCWE-732

Unrestricted access to Orion.UserSettings SWIS entity for low-privilege users

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
SolarWinds · Orion