Unprotected Transport of Credentials (HSTS) Vulnerability
Vulnerability Description
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-35246
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Justo Socarras
References
More from SolarWinds
View All →Affected Vendor
SolarWinds
View all reports →