← volver
CVE-2021-35244medium

Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6.8epss 5.8%
probabilidad de explotación
5.8%top 7% de las CVE
explotación observada
noninguna fuente lo reporta
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote code execution.
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
Productos afectados
SolarWinds · Orion Platform