New Vulnerabilities Disclosed in SolarWinds Products
ID: fe291094-e7e7-511a-a9b4-b0cbd864c8c8
STIX ID: report--fe291094-e7e7-511a-a9b4-b0cbd864c8c8
Feed Name: Arctic Wolf Blog
Threat Score
Researchers disclosed an RCE (CVE-2021-25274) in SolarWinds Orion and two LPEs (CVE-2021-25275 in Orion and CVE-2021-25276 in Serv-U FTP); TrustWave plans to release public proof-of-concept code, increasing exploitation risk. SolarWinds has released patches and vendors and defenders (Arctic Wolf) strongly recommend immediate upgrades, verifying Orion is not internet-exposed, and following secure configuration guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
