ZeroHour

CVE-2021-35226

CVSS 3.1
6.5 medium
EPSS
<1%p40
Published
()
Modified
Description

An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.

Vendors
solarwinds
Products
network configuration manager
Weakness
CWE-326
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.