SolarWinds Orion Platform < 2020.2.6 HF1 Multiple Vulnerabilities

critical Nessus Plugin ID 154339

Synopsis

An application running on the remote host is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the version of SolarWinds Orion Platform is prior to 2020.2.6 HF1. It is, therefore, affected by multiple vulnerabilities:

- A command injection vulnerability in the EmailWebPage API. An authenticated, remote attacker can exploit this to execute arbitrary commands.(CVE-2021-35220)
- An arbitrary file read vulnerability in ExportToPdfCmd. An authenticated, remote attacker can exploit this to read arbitrary files and disclose sensitive information. (CVE-2021-35219)
- An improper access control tampering vulnerability. An authenticated, remote attacker can exploit this to add arbitrary SMTP servers to the server configuration. (CVE-2021-35221)
- Multiple stored cross-site scripting vulnerabilities. A cross-site scripting (XSS) vulnerability exists due to improper validation of user-supplied input before returning it to users. An unauthenticated, remote attacker can exploit this, by convincing a user visit a URL, to execute arbitrary script code in a user's browser session. (CVE-2021-35238, CVE-2021-35239, CVE-2021-35240)
- A reflected cross-site scripting vulnerability. A cross-site scripting (XSS) vulnerability exists due to improper validation of user-supplied input before returning it to users. An unauthenticated, remote attacker can exploit this, by convincing a user to click a specially crafted URL, to execute arbitrary script code in a user's browser session. (CVE-2021-35222)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to SolarWinds Orion Platform 2020.2.6 HF1 or later.

See Also

http://www.nessus.org/u?8c68109e

Plugin Details

Severity: Critical

ID: 154339

File Name: solarwinds_orion_2020_2_6_hf1.nasl

Version: 1.4

Type: combined

Agent: windows

Family: CGI abuses

Published: 10/22/2021

Updated: 5/9/2022

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2021-35220

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2021-35222

Vulnerability Information

CPE: cpe:/a:solarwinds:orion_platform

Required KB Items: installed_sw/SolarWinds Orion Core

Exploit Ease: No known exploits are available

Patch Publication Date: 8/27/2021

Vulnerability Publication Date: 8/27/2021

Reference Information

CVE: CVE-2021-35219, CVE-2021-35220, CVE-2021-35221, CVE-2021-35222, CVE-2021-35238, CVE-2021-35239, CVE-2021-35240

IAVA: 2021-A-0477-S