VendorsSolarwindsnetwork_performance_monitorany version
Vulnerabilities

Solarwinds Network Performance Monitor any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-31474
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12213.
Published 2021-05-21 · Modified
10.0EPSS 0.939
CVE-2018-13442
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
Published 2019-07-16 · Modified
8.8EPSS 0.017
CVE-2021-35225
Netpath Horizontal Privilege Escalation Vulnerability: NPM 2020.2.5
Published 2021-10-21 · Modified
6.4EPSS 0.008
CVE-2017-9538
The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other words, the denial of service is caused by an incorrect implementation of a directory-traversal protection mechanism.
Published 2017-10-02 · Modified
4.9EPSS 0.024