Description
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
No analysis available yet.
Remediation
Vendor Solution
SolarWinds recommends to upgrade to the latest available version of Engineer's Toolset.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21889 | The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users. |
References
History
Fri, 25 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2025-04-25T18:18:44.414Z
Reserved: 2021-06-22T00:00:00.000Z
Link: CVE-2021-35246
Updated: 2024-08-04T00:33:51.305Z
Status : Modified
Published: 2022-11-23T17:15:09.943
Modified: 2024-11-21T06:12:08.733
Link: CVE-2021-35246
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD