CVE-2020-14005

HIGH

SolarWinds Orion Network Performance Monitor - Remote Code Execution via Event Definition

Title source: llm
STIX 2.1

Description

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-063/
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-065/

Scores

CVSS v3 8.8
EPSS 0.1043
EPSS Percentile 93.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
solarwinds/orion_network_performance_monitor 2019.4 hotfix2
solarwinds/orion_web_performance_monitor 2019.4.1
Published Jun 24, 2020
Tracked Since Feb 18, 2026