CVE-2021-25274
https://notcve.org/view.php?id=CVE-2021-25274
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process. Additionally, upon processing of such messages, the service deserializes them in insecure manner, allowing remote arbitrary code execution as LocalSystem. El Collector Service en SolarWinds Orion Platform versiones anteriores a 2020.2.4 usa MSMQ (Microsoft Message Queue) y no establece permisos en sus queues privadas. Como resultado, unos clientes no autenticados remotos pueden enviar mensajes hacia el puerto TCP 1801 que el Collector Service procesará. • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/full-system-control-with-new-solarwinds-orion-based-and-serv-u-ftp-vulnerabilities • CWE-502: Deserialization of Untrusted Data •
CVE-2021-25275
https://notcve.org/view.php?id=CVE-2021-25275
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database. SolarWinds Orion Platform versiones anteriores a 2020.2.4, tal como la utilizan varios productos SolarWinds, instala y usa un servidor SQL Server y almacena las credenciales de la base de datos para acceder a este servidor en un archivo que pueden leer los usuarios sin privilegios. • https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/full-system-control-with-new-solarwinds-orion-based-and-serv-u-ftp-vulnerabilities • CWE-798: Use of Hard-coded Credentials •
CVE-2020-28001 – SolarWinds Serv-U FTP Server 15.2.1 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2020-28001
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. SolarWinds Serv-U versiones anteriores a 15.2.2, permite un ataque de tipo XSS almacenado autenticado SolarWinds Serv-U FTP Server versions through 15.2.1 do not correctly sanitize and validate the user-supplied directory names, allowing malicious users to create directories that when clicked on (in the breadcrumb menu) will trigger cross site scripting payloads. • http://packetstormsecurity.com/files/161400/SolarWinds-Serv-U-FTP-Server-15.2.1-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2021/Feb/37 https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-2-2_release_notes.htm https://www.themissinglink.com.au/security-advisories-cve-2020-28001 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-27994 – SolarWinds Serv-U FTP Server 15.2.1 Path Traversal
https://notcve.org/view.php?id=CVE-2020-27994
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. SolarWinds Serv-U versiones anteriores a 15.2.2, permite un Salto de Directorio autenticado SolarWinds Serv-U File Server versions through 15.2.1 do not correctly validate path information, allowing the disclosure of files and directories outside of the user's home directory via a specially crafted GET request. • http://packetstormsecurity.com/files/161399/SolarWinds-Serv-U-FTP-Server-15.2.1-Path-Traversal.html http://seclists.org/fulldisclosure/2021/Feb/36 https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-2-2_release_notes.htm https://www.themissinglink.com.au/security-advisories-cve-2020-27994 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2020-35482
https://notcve.org/view.php?id=CVE-2020-35482
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. SolarWinds Serv-U versiones anteriores a 15.2.2, permite un ataque de tipo XSS reflejado autenticado • https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-2-2_release_notes.htm • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •