SB2021012201 - Multiple vulnerabilities in SolarWinds Orion Platform and Network Performance Monitor



SB2021012201 - Multiple vulnerabilities in SolarWinds Orion Platform and Network Performance Monitor

Published: January 22, 2021

Security Bulletin ID SB2021012201
Severity
Medium
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 secuirty vulnerabilities.


1) Path traversal (CVE-ID: CVE-2020-27871)

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within VulnerabilitySettings.aspx in SolarWinds Network Performance Monitor. A remote user can send a specially crafted HTTP request and create arbitrary files on the system in arbitrary directories.

Successful exploitation of the vulnerability can lead to arbitrary code execution in the context of SYSTEM account.


2) Information disclosure (CVE-ID: CVE-2020-27870)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application within ExportToPDF.aspx in SolarWinds Network Performance Monitor. A remote attacker can gain unauthorized access to sensitive information in the context of SYSTEM account.


3) SQL injection (CVE-ID: CVE-2020-27869)

The vulnerability allows a remote user to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data within the WriteToFile method in SolarWinds Network Performance Monitor. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.

Successful exploitation of this vulnerability may allow a remote attacker to escalate privileges and reset the password for the Admin user.


4) Input validation error (CVE-ID: CVE-2020-14005)

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input within the ExecuteVBScript and ExecuteExternalProgram methods in SolarWinds Network Performance Monitor. A remote authenticated user can pass specially crafted input to the application and execute arbitrary code with SYSTEM privileges.


Remediation

Install update from vendor's website.