Network Management
Remote Code Execution CVE Frequently Asked Questions
A list of frequently asked questions and responses related to the recently patched CVEs.
First published date
Last published date
Overview
Several CVEs were identified and patched in Orion 2020.2.5, and this article provides additional context about the vulnerabilities. These vulnerabilities are listed as fixed per the Orion Platform 2020.2.5 Release Notes:
https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/release_notes/orion_platform_2020-2-5_release_notes.htm
Product section
Resolution
- Is this vulnerability related to Sunburst?
- No, it is not. SolarWinds has always been committed to working with customers and other organizations to identify and remediate any vulnerabilities across our product portfolio in a responsible way. These vulnerabilities were reported by Trend Micro ZDI and have been fixed in Orion 2020.2.5 by our development team.
- Trend Micro ZDI is a leading threat detection that responsibly reports product vulnerabilities to companies as they are discovered prior to a broader announcement to allow companies to develop remediations to protect their customers.
- What versions are impacted?
- All Orion platform versions prior to 2020.2.5
- Do I need to upgrade immediately?
- Critical and high severity vulnerabilities have been fixed in this latest version are linked to a published CVE. There are CVE-IDs with Pending status as they still have not received their CVE ID but the vulnerabilities have been addressed in Orion 2020.2.5.
- Customers are encouraged to update to this latest version to address these publicly known vulnerabilities.
- Are there any workarounds or mitigation steps to the following vulnerabilities?
- The following workaround is available to address the Job Scheduler Remote Code Execution:
- Is an upgrade required to resolve the vulnerabilities?
- The workaround listed above applies only to the Job Scheduler RCE, an upgrade is required to address the other vulnerabilities.
- What is the CVE Score for each vulnerability?
- Documented in the release notes here: https://documentation.solarwinds.com/en/Success_Center/orionplatform/content/release_notes/Orion_Platform_2020-2-5_release_notes.htm
- Is there a security advisory that I can subscribe to get information about future issues?
- Not at the moment but we will consider it for future product security advisories.
- Does 2020.2.5 include the digital certificate update?
- Yes, this and all future versions will include the digital certificate update.
- I recently upgraded to 2020.2.4. Should I upgrade?
- Yes, we recommend upgrading to 2020.2.5 as it addresses several vulnerabilities as well as providing additional functionality. All updates are outlined in the Release Notes.
- We’ve made updates to our installer to make this an easy update for you. These Installer videos may help in your upgrade: