CVE-2021-35218
HIGHSolarWinds Orion Platform < 2020.2.6 - Unauthenticated Remote Code Execution via Web Console Chart Endpoint
Title source: llmDescription
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server
References (3)
Core 3
Core References
Not Applicable, Vendor Advisory x_refsource_misc
https://documentation.solarwinds.com/en/success_center/patchman/content/release_notes/patchman_2020-2-6_release_notes.htm
Vendor Advisory x_refsource_misc
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35218
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-1248/
Scores
CVSS v3
8.9
EPSS
0.1488
EPSS Percentile
94.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Details
CWE
CWE-502
Status
published
Products (1)
solarwinds/orion_platform
< 2020.2.6
Published
Sep 01, 2021
Tracked Since
Feb 18, 2026