The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Http Solarwinds Orion Platform | — | Upgrade SolarWinds Orion Platform 2020 to version 2020.2.1 HF 2 or laterUpgrade SolarWinds Orion Platform 2019.4 to version 2019.4 HF 6 or latestUpgrade SolarWinds Orion Platform to the latest version | Dec 29, 2020 | Dec 26, 2020 |
| Solarwinds Orion_platform | — | Upgrade SolarWinds Orion Platform to the latest version | May 29, 2026 | Dec 29, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub