Orion Platform
Vendor:
First CVE: Mar 1, 2019 · Active for 7 years
49
Total CVEs
More Total CVEs than 98% of tracked products
9.8
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
2.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Orion Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2019
7 years ago
Most Recent CVE
Sep 13, 2023
1,048 days ago
CVE Severity & Scoring
Orion Platform49 CVEs
31%
57%
12%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (10.2%)
Network43 (87.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.0%)
Attack Complexity
Low49 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None39 (79.6%)
Unknown0 (0.0%)
Required10 (20.4%)
Privileges Required
Low21 (42.9%)
High20 (40.8%)
None8 (16.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10148CRITICAL The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to b | Dec 29, 2020 | 9.8 | 97 | YES | YES |
CVE-2022-36958HIGH SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute ar | Oct 20, 2022 | 8.8 | 74 | NO | NO |
CVE-2022-38108HIGH SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web C | Oct 20, 2022 | 7.2 | 73 | NO | YES |
CVE-2020-27871HIGH This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit | Feb 10, 2021 | 7.2 | 71 | NO | NO |
CVE-2022-38111HIGH SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web C | Feb 15, 2023 | 7.2 | 68 | NO | NO |
CVE-2023-23836HIGH SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level accou | Feb 15, 2023 | 7.2 | 67 | NO | NO |
CVE-2021-35218HIGH Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager We | Sep 1, 2021 | 8.8 | 67 | NO | NO |
CVE-2021-35215HIGH Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability. | Sep 1, 2021 | 8.8 | 67 | NO | NO |
CVE-2022-36961HIGH A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution. | Sep 30, 2022 | 8.8 | 62 | NO | NO |
CVE-2021-25274CRITICAL The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauth | Feb 3, 2021 | 9.8 | 49 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (49 CVEs).
CISA KEV
1 CVE
2.0% of CVEs· 98th percentile
Metasploit
1 CVE
2.0% of CVEs· 97th percentile
Nuclei
1 CVE
2.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (49 CVEs).
Media Mentions
Signals from CVEs in this product scope (49 CVEs).
Top CNAs Publishing CVEs For Orion Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2022.4.1 | 6 | 7.3 | 37.1% | 0 | 0 |
| 2022.3 | 7 | 7.6 | 27.4% | 0 | 1 |
| 2022.2 | 7 | 7.6 | 27.4% | 0 | 1 |
| 2020.2.6 | 12 | 7.4 | 22.3% | 0 | 1 |
| 2020.2.5 | 1 | 8.8 | 1.6% | 0 | 0 |
| 2020.2.4 | 1 | 8.8 | 1.6% | 0 | 0 |
| 2020.2.1 | 4 | 8.1 | 47.1% | 1 | 1 |
| 2020.2 | 3 | 9.1 | 32.4% | 1 | 1 |
| 2019.4 | 2 | 9.3 | 46.8% | 1 | 1 |
| 2019.2 | 3 | 7.0 | 1.7% | 0 | 0 |
| 2018.4 | 3 | 7.5 | 1.8% | 0 | 0 |