Security Advisory

CVE-2021-35234

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-12-20 20:08:25
Last updated 2024-09-16 18:59:20
Assigner SolarWinds
CVSS score 8.0
State PUBLISHED

Description

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.