CVE-2021-35235 Details
Description
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a debugger to closely monitor and control the execution of an application. If an attacker could successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure that may be valuable in targeting SWI with malicious intent.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://documentation.solarwinds.com/en/success_center/kss/content/release_notes/kss_9-8_release_notes.htm | CVE | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/CVE-2021-35235 | CVE | Release NotesVendor Advisory |
| https://documentation.solarwinds.com/en/success_center/kss/content/release_notes/kss_9-8_release_notes.htm | [email protected] | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/CVE-2021-35235 | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-11 | ASP.NET Misconfiguration: Creating Debug Binary | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| solarwinds kiwi syslog server | <= 9.7.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 28, 2021 | Initial Analysis | [email protected] |