Recent as of February 5, 2021, 2:30pm CST
FAQ: Security Advisory
COMMON CRITERIA
- If I’ve upgraded to Orion Platform versions 2019.4 HF6 or 2020.2.1 HF2, am I affected by SUNBURST or SUPERNOVA?
- Am I safe if I disconnect my Orion server from the internet?
- How is SolarWinds addressing SUNBURST and SUPERNOVA?
- Are SUNBURST and SUPERNOVA related?
- What are SUNSPOT, TEARDROP, and RAINDROP?
- How is SolarWinds responding to these security vulnerabilities?
- What programs is SolarWinds going to offer its customers?
- What actions should I take?
- How do I know what version I’m on?
- How do I know if my environment was exposed?
- How do I upgrade my Orion Platform version?
- My antivirus software is alerting on the of SolarWinds.Orion.Core.BusinessLayer.dll – am I infected?
- Some endpoint security tools flag old Orion installers left behind after upgrading to protected versions. Do these alerts mean that I am still at risk?
- Has the Department of Homeland Security issued an Emergency Directive on this vulnerability?
- Why does CISA recommend users split out the web server from the Orion Application server?
- What is SolarWinds doing to help find a solution?
- What if I can’t upgrade right now? How do I ensure the security of my Orion server?
- I have downloaded a file from my Customer Portal and want to verify it is legitimate. How can I do that?
- Where can I see a complete list of all Orion Platform versions, their status, and recommended actions?
- If your environment was compromised, why is it safe for us to install these updates/trust your code? OR What are you doing to prevent future incidents moving forward?
- I still have more questions about this issue and my environment’s security—who can I talk to?
- Why can’t you tell us more about what’s going on?
- What about the vulnerabilities disclosed by Trustwave?
- What about the issue disclosed by Sophos?
- What is SUPERNOVA?
- Is SUPERNOVA another supply chain attack?
- What indicators of compromise (IOCs) of the SUPERNOVA malware have you identified?
- How can I confirm if I’ve applied either the SUPERNOVA mitigation script or one of the SUPERNOVA security fixes to my Orion server(s)?
- What is SUNBURST?
- How extensive is the impact of SUNBURST?
- What should I do if I believe my environment has been compromised by the SUNBURST vulnerability?
- If my Orion server currently or previously had a SUNBURST vulnerable version, should I simply upgrade or should I rebuild my Orion server? What about my database?
- I want to manually check my version of the SolarWinds.Orion.Core.BusinessLayer.dll for the SUNBURST vulnerability. Do you know a way to do that?
- What indicators of compromise (IOCs) of the SUNBURST vulnerability have you identified?
- How do I know someone didn't exploit the SUNBURST vulnerability and move horizontally in my environment and compromise another system?
- What products are affected by the SUNBURST vulnerability?
- What products are NOT affected by the SUNBURST vulnerability?
- Why didn’t SolarWinds catch the SUNBURST vulnerability before it happened?
- With these processes in place how was your code compromised to insert the SUNBURST vulnerability?
- How many customers are potentially affected by SUNBURST vulnerability?
- Why were 33,000 customers mentioned in connection with the SUNBURST vulnerability?
- What is the Common Criteria framework?
- Where can I see a complete list of Orion Suite for Federal Government versions, their status and recommended actions?