Executive brief
The SolarWinds Orion API contains an authentication bypass vulnerability that allows a remote attacker to execute API commands without authentication. This flaw can lead to a full compromise of the affected SolarWinds instance.
Affected products
- SolarWinds Orion Platform 2019.4 HF 5, 2020.2, 2020.2 HF 1
Timeline
- 2020-12-29: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory