CVE-2021-35218

HIGH

SolarWinds Orion Platform < 2020.2.6 - Unauthenticated Remote Code Execution via Web Console Chart Endpoint

Title source: llm
STIX 2.1

Description

Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server

References (3)

Core 3

Scores

CVSS v3 8.9
EPSS 0.1488
EPSS Percentile 94.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-502
Status published
Products (1)
solarwinds/orion_platform < 2020.2.6
Published Sep 01, 2021
Tracked Since Feb 18, 2026