VulnerabilityAnalyzed
CVE-2024-0692
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability.
HIGH 8.8EPSS 92.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 92.2%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 92.25% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- solarwinds/security event manager
- Source
- psirt@solarwinds.com
References
- https://documentation.solarwinds.com/en/success_center/sem/content/release_notes/sem_2023-4-1_release_notes.htmRelease Notes
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-0692Vendor Advisory
- https://documentation.solarwinds.com/en/success_center/sem/content/release_notes/sem_2023-4-1_release_notes.htmRelease Notes
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-0692Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.