Rapid7 Vulnerability & Exploit Database

SolarWinds Orion Platform: Improper Privilege Management Vulnerability (CVE-2021-28674)

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7 Labs
Back to Search

SolarWinds Orion Platform: Improper Privilege Management Vulnerability (CVE-2021-28674)

Severity
6
CVSS
(AV:N/AC:L/Au:S/C:N/I:P/A:P)
Published
07/30/2021
Created
08/20/2021
Added
08/19/2021
Modified
08/19/2021

Description

The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the access control on Services/NodeManagement.asmx/DeleteObjNow is incorrect. To exploit this, an attacker must be authenticated and must have node management rights associated with at least one valid group on the platform.

Solution(s)

  • solarwinds-orion-platform-upgrade-2020_2_5

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;