Heap Overflow Vulnerability in Asset Explorer Agent from SolarWinds
CVE-2021-20109
What is CVE-2021-20109?
The Asset Explorer agent suffers from a vulnerability due to insufficient validation of HTTPS certificates, allowing attackers on the local network to impersonate the Asset Explorer server. An attacker can statically configure their IP to match the server's; thereby manipulating communication with the agent. The exploitation occurs when a malicious actor sends a NEWSCAN request to a listening agent, which can lead to a heap overflow in the AEAgent.cpp source file. This happens if a POST payload response exceeds the 0x2000-byte buffer limit, as it is converted to Unicode without proper size checks, leading to potential denial of service or arbitrary code execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Manage Engine Asset Explorer Agent 1.0.34
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved