CVE-2024-28075
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 78.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
- CVSS 3.1
- 8.0 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 78.03% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- solarwinds/access rights manager
- Source
- psirt@solarwinds.com
References
- https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htmRelease Notes
- https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htmProduct
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28075Vendor Advisory
- https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htmRelease Notes
- https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htmProduct
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28075Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.