Showing 3 vulnerabilities on this page for Orion

Signals CISA KEV Ransomware Nuclei
SolarWinds vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Unrestricted access to Orion.UserSettings SWIS entity for low-privilege users

It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.

CWE-732CWE-863Dec 20, 2021
CVSS6.8v3.1EPSS0.886%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

CWE-287CWE-288CWE-306Dec 29, 20201 related artifact
CVSS9.8v3.1EPSS92%PoCs3SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SolarWinds Orion Uncontrolled Search Path Element

SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

CWE-427Mar 1, 2019
CVSS9.8v3.0EPSS2.78%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX