CVE-2024-28075

Scores

EPSS

0.736medium73.6%
0%20%40%60%80%100%

Percentile: 73.6%

CVSS

8.0high3.x
0246810

CVSS Score: 8.0/10

All CVSS Scores

CVSS 3.x
8.0

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.

We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

502CWE-502

Related Vulnerabilities

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: access_rights_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:*",      "versionEndExcluding": "2023.2.4",      "vulnerable": true    }  ],  "operator": "OR"...

Source: nvd

End of list