7.8
CVSSv3

CVE-2021-25275

Published: 03/02/2021 Updated: 08/02/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SolarWinds Orion Platform prior to 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

solarwinds orion platform

Github Repositories

My notes for 1 hour OpenVAS class

Notes taken while learnining OpenVAS Terminology NVT - Network Vunlerability Test Scan Definitions GVM - Greenbone Vunlerability Management GSM - Greenbone Security Manager - Commercial Vulnerability Management CPE - Common Platform Enumeration Source Addtion - Open Source version of OpenVAS Steps to install OpenVAS on Kali Make sure you are up to date sudo apt update -y su