Vulnerability record · CVE-2021-35215 · published 1 September 2021
CVE-2021-35215: SolarWinds Orion Platform insecure deserialization RCE
Solarwinds · Orion Platform
The SolarWinds Orion Platform (version 2020.2.5 per the record) contains an insecure deserialization flaw (CWE-502) that allows remote code execution. Because the platform is a central monitoring and management system, a successful exploit can compromise a high-value host that often holds broad network and credential access.
Description
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and very high EPSS, though exploitation requires authentication and no KEV listing or known exploit code is documented.
What it is
The SolarWinds Orion Platform (version 2020.2.5 per the record) contains an insecure deserialization flaw (CWE-502) that allows remote code execution. Because the platform is a central monitoring and management system, a successful exploit can compromise a high-value host that often holds broad network and credential access.
Impact
An authenticated attacker gains remote code execution on the Orion server, with high confidentiality, integrity and availability impact per the CVSS vector. This can lead to full control of the monitoring host and any credentials or managed systems it touches.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction; the record states authentication is required, and the vector reflects low privileges (PR:L). No specific endpoint or interface is identified in the supplied data.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.697, 99.3rd percentile), indicating elevated likelihood of attempted exploitation. References include a vendor patch advisory and a ZDI advisory, but no public exploit code is confirmed in the record.
What to do
- Apply the vendor patch referenced in the SolarWinds security advisory for CVE-2021-35215 (upgrade from Orion Platform 2020.2.5 to the fixed release).
- Restrict network access to the Orion Platform web interface and management ports to trusted administrative networks only.
- Enforce least privilege and review accounts with access to Orion, since exploitation requires authentication.
- Monitor and alert on deserialization-related errors or unexpected child processes spawned by Orion services.
- If patching is delayed, isolate the Orion server and increase logging around authentication and application activity.
Detection
- Hunt for unusual child processes (cmd.exe, powershell.exe, wscript.exe) spawned by Orion Platform service processes.
- Review Orion application and web server logs for deserialization exceptions or anomalous serialized payload patterns.
- Alert on authentication events to Orion from unusual source IPs or accounts followed by process creation on the host.
- Monitor for outbound connections from the Orion server to unexpected destinations that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://documentation.solarwinds.co/enm/success_center/orionplatform/content/release_notes/orion_platform_2020-2-6_relea | Broken Link |
| https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm | ProductVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35215 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1245/ | Third Party AdvisoryVDB Entry |
| https://documentation.solarwinds.co/enm/success_center/orionplatform/content/release_notes/orion_platform_2020-2-6_relea | Broken Link |
| https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm | ProductVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35215 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-1245/ | Third Party AdvisoryVDB Entry |
Track CVE-2021-35215 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35215), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.