Known exploits

The Orion platform's size has made it a repeated source of serious vulnerabilities. The classes include an authentication bypass in the Orion API (reaching authenticated and administrative functionality unauthenticated), deserialization and other remote-code-execution flaws in the web and service components (several reaching SYSTEM because Orion services run with high privilege), and issues across the many Orion modules. Some are pre-authentication. For a target, fingerprint the exact Orion Platform version and the installed modules and match them to the applicable advisory, since the vulnerable component and whether it needs authentication are version- and module-specific. A successful exploit yields code execution on the Orion server, which holds the managed estate's credentials and sits centrally in the network, so it is a high-impact compromise. Orion's central trust is also why it was the vehicle for a major supply-chain incident.

bash
# fingerprint version + modules, then match to the advisory
curl -sk https://<target>/Orion/Login.aspx | grep -ioE 'Orion Platform [0-9.]+'
curl -sk https://<target>/SolarWinds/InformationService/v3/Json/      # API surface present?
# the exploit is version/module-specific: API auth bypass, deserialization RCE, or a
# module-specific flaw; match the build to the SolarWinds advisory. SYSTEM is common.

Exploitation notes#

  • Fingerprint version and modules; the applicable exploit (API auth bypass, deserialization RCE, module flaw) and whether it is pre-auth are specific to the build, so the mapping is the key step.
  • Orion services run with high privilege, so successful RCE is frequently SYSTEM on the Orion server, which then yields the stored credentials for the whole estate.
  • The API authentication bypass is notable because it reaches administrative functionality unauthenticated; check whether the API surface is present and in range.
  • Pre-auth chains are the cleanest; post-auth ones pair with the authentication routes. Orion's central position makes any of these high-impact.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more