VYPR
High severity8.0NVD Advisory· Published Dec 20, 2021· Updated Jun 17, 2026

CVE-2021-35234

CVE-2021-35234

Description

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:*range: <=2020.2.5
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:-:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix1:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:orion_platform:2020.2.6:hotfix2:*:*:*:*:*:*
  • SolarWinds/Orion Corev5
    Range: 2020.2.6 HF 2 and previous versions

Patches

Vulnerability mechanics

References

12

News mentions

0

No linked articles in our index yet.