CVE-2021-25275
SolarWinds Platform vulnerability analysis and mitigation

Overview

SolarWinds Orion Platform before 2020.2.4 contains a vulnerability (CVE-2021-25275) where database credentials used to access the SQL Server backend are stored in a file readable by unprivileged users. The vulnerability was discovered in early 2021 and affects various SolarWinds products that use the Orion Platform (NVD, Trustwave).

Technical details

The vulnerability exists because database credentials to access the backend are stored in a configuration file that is readable by any authenticated Windows user. The credentials provide database owner (DBO) access to the SWNetPerfMon.DB database. An unprivileged user who can log in locally or via RDP can read and decrypt the database login details from the file, including the username and password (Trustwave).

Impact

By exploiting this vulnerability, attackers can gain complete access to the SOLARWINDS_ORION database, allowing them to steal sensitive information or add new admin-level users to the Orion applications by modifying authentication data stored in the database's Accounts table (Trustwave, ZDNET).

Exploitability

The vulnerability requires local or RDP access to the system running SolarWinds Orion. Once an attacker has such access, they can easily read and decrypt the stored credentials using a simple decryption utility. To the best of Trustwave's knowledge, this vulnerability was not exploited in the wild before patches were released (Trustwave).

Mitigation and workarounds

SolarWinds has released patches to address this vulnerability in Orion Platform version 2020.2.4. Organizations are strongly recommended to upgrade to this version as soon as possible to protect against potential exploitation (ZDNET).

Community reactions

The vulnerability received heightened scrutiny due to its discovery shortly after the major SolarWinds supply chain attack in December 2020. SolarWinds acknowledged the vulnerability and emphasized their commitment to working with customers and organizations to identify and remediate vulnerabilities across their product portfolio (ZDNET).

Additional resources


SourceThis report was generated using AI

Related SolarWinds Platform vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-52606CRITICAL9.8
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesFeb 11, 2025
CVE-2024-45715MEDIUM5.2
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesOct 16, 2024
CVE-2024-52612MEDIUM4.8
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesFeb 11, 2025
CVE-2024-45717MEDIUM4.8
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesDec 04, 2024
CVE-2024-52611LOW3.5
  • SolarWinds Platform logoSolarWinds Platform
  • cpe:2.3:a:solarwinds:solarwinds_platform
NoYesFeb 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management