{"api_version":"1","generated_at":"2026-07-23T12:19:55+00:00","cve":"CVE-2021-35217","urls":{"html":"https://cve.report/CVE-2021-35217","api":"https://cve.report/api/cve/CVE-2021-35217.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-35217","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-35217"},"summary":{"title":"CVE-2021-35217","description":"Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data.","state":"PUBLIC","assigner":"psirt@solarwinds.com","published_at":"2021-09-08 14:15:00","updated_at":"2021-11-03 20:22:00"},"problem_types":["CWE-502"],"metrics":[],"references":[{"url":"https://support.solarwinds.com/SuccessCenter/s/article/Patch-Manager-2020-2-6-Hotfix-1-Release-Notes?language=en_US","name":"https://support.solarwinds.com/SuccessCenter/s/article/Patch-Manager-2020-2-6-Hotfix-1-Release-Notes?language=en_US","refsource":"CONFIRM","tags":[],"title":"Success Center","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/orion_platform_2020-2-6_release_notes.htm","name":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/orion_platform_2020-2-6_release_notes.htm","refsource":"MISC","tags":[],"title":"Orion Platform 2020.2.6 Release Notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm","name":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm","refsource":"MISC","tags":[],"title":"Secure Configuration for the Orion Platform","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35217","name":"https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35217","refsource":"MISC","tags":[],"title":"SolarWinds Trust Center Security Advisories | CVE-2021-35217","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-21-1247/","name":"https://www.zerodayinitiative.com/advisories/ZDI-21-1247/","refsource":"MISC","tags":[],"title":"ZDI-21-1247 | Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-35217","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35217","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Jangggggg working with Trend Micro Zero Day Initiative","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"35217","vulnerable":"1","versionEndIncluding":"2020.2.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"solarwinds","cpe5":"patch_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@solarwinds.com","DATE_PUBLIC":"2021-09-02T13:14:00.000Z","ID":"CVE-2021-35217","STATE":"PUBLIC","TITLE":"Insecure Deserialization of untrusted data causing Remote code execution vulnerability. "},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Orion Platform ","version":{"version_data":[{"version_affected":"<","version_name":"2020.2.5 and previous versions","version_value":"2020.2.6"}]}}]},"vendor_name":"SolarWinds"}]}},"credit":[{"lang":"eng","value":"Jangggggg working with Trend Micro Zero Day Initiative "}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":8.9,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Insecure Deserialization of untrusted data causing Remote code execution vulnerability."}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm","name":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm"},{"refsource":"MISC","url":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/orion_platform_2020-2-6_release_notes.htm","name":"https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/orion_platform_2020-2-6_release_notes.htm"},{"refsource":"MISC","url":"https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35217","name":"https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35217"},{"refsource":"MISC","name":"https://www.zerodayinitiative.com/advisories/ZDI-21-1247/","url":"https://www.zerodayinitiative.com/advisories/ZDI-21-1247/"}]},"solution":[{"lang":"eng","value":"SolarWinds  recommends  upgrading  to  both  the  latest  version  of Patch Manager and Orion Integration Module as soon as it becomes available."}],"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-09-08 14:15:00","lastModifiedDate":"2021-11-03 20:22:00","problem_types":["CWE-502"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:solarwinds:patch_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"2020.2.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"35217","Ordinal":"210708","Title":"CVE-2021-35217","CVE":"CVE-2021-35217","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"35217","Ordinal":"1","NoteData":"Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted data.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"35217","Ordinal":"2","NoteData":"2021-09-08","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"35217","Ordinal":"3","NoteData":"2021-10-28","Type":"Other","Title":"Modified"}]}}}