CVE-2021-31475
SolarWinds Orion Job Scheduler JobRouterService Improper Authorization Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authentication is required to exploit this vulnerability. The specific flaw exists within the JobRouterService WCF service. The issue is due to the WCF service configuration, which allows a critical resource to be accessed by unprivileged users. An attacker can leverage this vulnerability to execute code in the context of an administrator. Was ZDI-CAN-12007.
Esta vulnerabilidad permite a atacantes remotos ejecutar código arbitrario en instalaciones afectadas de SolarWinds Orion Job Scheduler versión 2020.2.1 HF 2. Es requerida una autenticación para explotar esta vulnerabilidad. El fallo específico se presenta dentro del servicio WCF JobRouterService. El problema es debido a la configuración del servicio WCF, que permite a usuarios no privilegiados acceder a un recurso crítico. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto de un administrador. Fue ZDI-CAN-12007
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler. Authentication is required to exploit this vulnerability.
The specific flaw exists within the JobRouterService WCF service. The issue is due to the WCF service configuration, which allows a critical resource to be accessed by unprivileged users. An attacker can leverage this vulnerability to execute code in the context of an administrator.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-16 CVE Reserved
- 2021-05-21 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-21-605 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Solarwinds Search vendor "Solarwinds" | Orion Job Scheduler Search vendor "Solarwinds" for product "Orion Job Scheduler" | 2020.2.1 Search vendor "Solarwinds" for product "Orion Job Scheduler" and version "2020.2.1" | hotfix2 |
Affected
|