Remote Code Execution Vulnerability in SolarWinds Network Performance Monitor
CVE-2021-31474
What is CVE-2021-31474?
This vulnerability affects SolarWinds Network Performance Monitor 2020.2.1, enabling remote attackers to execute arbitrary code without authentication. The flaw lies within the SolarWinds.Serialization library due to inadequate validation of user-supplied data, leading to the deserialization of untrusted data. An attacker can exploit this vulnerability to run code in the context of the SYSTEM account, which may compromise the integrity and security of the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Network Performance Monitor 2020.2.1
References
EPSS Score
53% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved