CVE-2021-35226

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
10/10/2022
Last modified:
03/08/2023

Description

An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:network_configuration_manager:*:*:*:*:*:*:*:* 2020.2.5 (including)