CVE-2021-35215

HIGH

Orion Platform <2020.2.5 - RCE

Title source: llm
STIX 2.1

Description

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

Exploits (1)

nomisec WORKING POC 47 stars
by Y4er · poc
https://github.com/Y4er/CVE-2021-35215

Scores

CVSS v3 8.9
EPSS 0.8276
EPSS Percentile 99.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-502
Status published
Products (1)
solarwinds/orion_platform < 2020.2.5
Published Sep 01, 2021
Tracked Since Feb 18, 2026