Orion Platform

Vendor:

First CVE: Mar 1, 2019 · Active for 7 years

49
Total CVEs
More Total CVEs than 98% of tracked products
9.8
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
2.0%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Orion Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2019
7 years ago
Most Recent CVE
Sep 13, 2023
1,048 days ago

CVE Severity & Scoring

Orion Platform49 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local5 (10.2%)
Network43 (87.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low49 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None39 (79.6%)
Unknown0 (0.0%)
Required10 (20.4%)
Privileges Required
Low21 (42.9%)
High20 (40.8%)
None8 (16.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to b
Dec 29, 20209.897YESYES
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute ar
Oct 20, 20228.874NONO
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web C
Oct 20, 20227.273NOYES
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit
Feb 10, 20217.271NONO
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web C
Feb 15, 20237.268NONO
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level accou
Feb 15, 20237.267NONO
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager We
Sep 1, 20218.867NONO
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.
Sep 1, 20218.867NONO
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.
Sep 30, 20228.862NONO
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauth
Feb 3, 20219.849NONO

Exploit Exposure

Signals from CVEs in this product scope (49 CVEs).

CISA KEV
1 CVE
2.0% of CVEs· 98th percentile
Metasploit
1 CVE
2.0% of CVEs· 97th percentile
Nuclei
1 CVE
2.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (49 CVEs).

Media Mentions

Signals from CVEs in this product scope (49 CVEs).

Top CNAs Publishing CVEs For Orion Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2022.4.167.337.1%00
2022.377.627.4%01
2022.277.627.4%01
2020.2.6127.422.3%01
2020.2.518.81.6%00
2020.2.418.81.6%00
2020.2.148.147.1%11
2020.239.132.4%11
2019.429.346.8%11
2019.237.01.7%00
2018.437.51.8%00