Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2021-25275

EPSS 0.11% · P28
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-25275

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can read database login details from that file, including the login name and its associated password. Then, the credentials can be used to get database owner access to the SWNetPerfMon.DB database. This gives access to the data collected by SolarWinds applications, and leads to admin access to the applications by inserting or changing authentication data stored in the Accounts table of the database.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Solarwinds Orion Platform 信任管理问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Solarwinds Orion Platform是美国Solarwinds公司的一套网络故障和网络性能管理平台。该平台可对网络设备提供实时监测和分析,并支持定制网页介面、多种用户意见和对整个网络进行地图式浏览等。 SolarWinds Orion Platform before 2020.2. 存在信任管理问题漏洞,任何能够访问文件系统的用户都可以从该文件读取数据库登录详细信息,包括登录名及其关联的密码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2021-25275

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-25275

登录查看更多情报信息。

Same Patch Batch · n/a · 2021-02-03 · 59 CVEs total

CVE-2020-288957.3 HIGHinteger overflow in calloc
CVE-2021-233314.4 MEDIUMInsecure Temporary File
CVE-2020-25208JetBrains YouTrack 授权问题漏洞
CVE-2020-29166RainbowFish PacsOne Server 代码问题漏洞
CVE-2020-29163RainbowFish PacsOne Server SQL注入漏洞
CVE-2020-29164RainbowFish PacsOne Server 跨站脚本漏洞
CVE-2020-29165RainbowFish PacsOne Server 访问控制错误漏洞
CVE-2021-25761Jetbrains JetBrains Ktor framework 加密问题漏洞
CVE-2021-25763JetBrains Ktor framework 加密问题漏洞
CVE-2021-25762Jetbrains JetBrains Ktor framework 环境问题漏洞
CVE-2021-25765Jetbrains JetBrains YouTrack 跨站请求伪造漏洞
CVE-2021-25760JetBrains Hub 信息泄露漏洞
CVE-2021-25766Jetbrains JetBrains YouTrack 安全漏洞
CVE-2021-25767Jetbrains JetBrains YouTrack 信息泄露漏洞
CVE-2021-25768JetBrains YouTrack 安全漏洞
CVE-2021-25769Jetbrains JetBrains YouTrack 安全漏洞
CVE-2021-25770JetBrains YouTrack 代码注入漏洞
CVE-2021-25771JetBrains YouTrack 信息泄露漏洞
CVE-2021-25773JetBrains TeamCity 跨站脚本漏洞
CVE-2021-25772JetBrains TeamCity 安全漏洞

Showing top 20 of 59 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-25275

No comments yet


Leave a comment