Vendor CVEs
SolarWinds
All CVEs
342 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-40551 | Cri | 0.85 | 9.8 | 0.84 | KEV | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | |
| CVE-2021-35211 | Cri | 0.84 | 9.0 | 0.91 | KEV | Jul 14, 2021 | Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File… | |
| CVE-2025-26399 | Cri | 0.83 | 9.8 | 0.88 | KEV | Sep 23, 2025 | SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which… | |
| CVE-2020-10148 | Cri | 0.83 | 9.8 | 0.92 | KEV | Dec 29, 2020 | The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds… | |
| CVE-2024-28987 | Cri | 0.82 | 9.1 | 0.93 | KEV | Aug 21, 2024 | The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data. | |
| CVE-2024-28986 | Cri | 0.82 | 9.8 | 0.85 | KEV | Aug 13, 2024 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been… | |
| CVE-2024-28995 | Hig | 0.79 | 8.6 | 1.00 | KEV | Jun 6, 2024 | SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine. | |
| CVE-2025-40536 | Hig | 0.74 | 8.1 | 0.72 | KEV | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality. | |
| CVE-2021-31474 | Cri | 0.71 | 9.8 | 0.94 | May 21, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library.… | ||
| CVE-2012-2576 | Cri | 0.71 | 9.8 | 0.59 | Dec 20, 2017 | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field. | ||
| CVE-2016-2345 | Cri | 0.71 | 9.8 | 0.51 | Mar 17, 2016 | Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string. | ||
| CVE-2025-40553 | Cri | 0.69 | 9.8 | 0.60 | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication. | ||
| CVE-2017-7722 | Cri | 0.69 | 10.0 | 0.13 | Apr 12, 2017 | In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker… | ||
| CVE-2016-4350 | Cri | 0.69 | 9.8 | 0.70 | May 9, 2016 | Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) ScriptSchedule parameter in the… | ||
| CVE-2025-40554 | Cri | 0.68 | 9.8 | 0.57 | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk. | ||
| CVE-2025-40552 | Cri | 0.68 | 9.8 | 0.50 | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication. | ||
| CVE-2024-28988 | Cri | 0.67 | 9.8 | 0.39 | Sep 1, 2025 | SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous… | ||
| CVE-2021-25274 | Cri | 0.67 | 9.8 | 0.36 | Feb 3, 2021 | The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process.… | ||
| CVE-2019-8917 | Cri | 0.67 | 9.8 | 0.36 | Feb 18, 2019 | SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The… | ||
| CVE-2016-3643 | Hig | 0.66 | 7.8 | 0.04 | KEV | Jun 17, 2016 | SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd." | |
| CVE-2024-28075 | Cri | 0.65 | 9.0 | 0.78 | May 14, 2024 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing… | ||
| CVE-2024-0692 | Hig | 0.65 | 8.8 | 0.92 | Mar 1, 2024 | The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution. | ||
| CVE-2019-12181 | Hig | 0.65 | 8.8 | 0.66 | Jun 17, 2019 | A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. | ||
| CVE-2016-3642 | Cri | 0.65 | 9.8 | 0.13 | Jun 17, 2016 | The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. | ||
| CVE-2024-23472 | Cri | 0.64 | 9.6 | 0.19 | Jul 17, 2024 | SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM. | ||
| CVE-2024-23469 | Cri | 0.64 | 9.6 | 0.18 | Jul 17, 2024 | SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. | ||
| CVE-2022-36958 | Hig | 0.64 | 8.8 | 0.83 | Oct 20, 2022 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2021-35217 | Hig | 0.64 | 8.9 | 0.73 | Sep 8, 2021 | Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted… | ||
| CVE-2021-35218 | Hig | 0.64 | 8.9 | 0.76 | Sep 1, 2021 | Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server | ||
| CVE-2021-35216 | Hig | 0.64 | 8.9 | 0.81 | Sep 1, 2021 | Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution. | ||
| CVE-2021-27258 | Cri | 0.64 | 9.8 | 0.04 | Apr 14, 2021 | This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results… | ||
| CVE-2020-35481 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2021 | SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. | ||
| CVE-2020-15543 | Cri | 0.64 | 9.8 | 0.02 | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path. | ||
| CVE-2020-15542 | Cri | 0.64 | 9.8 | 0.02 | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command. | ||
| CVE-2020-15541 | Cri | 0.64 | 9.8 | 0.07 | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution. | ||
| CVE-2019-3980 | Cri | 0.64 | 9.8 | 0.05 | Oct 8, 2019 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an… | ||
| CVE-2019-9546 | Cri | 0.64 | 9.8 | 0.03 | Mar 1, 2019 | SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service. | ||
| CVE-2018-16791 | Cri | 0.64 | 9.8 | 0.02 | Dec 5, 2018 | In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to… | ||
| CVE-2024-28074 | Cri | 0.63 | 9.6 | 0.11 | Jul 17, 2024 | It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability. | ||
| CVE-2024-23475 | Cri | 0.63 | 9.6 | 0.02 | Jul 17, 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information. | ||
| CVE-2024-23471 | Cri | 0.63 | 9.6 | 0.01 | Jul 17, 2024 | The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution. | ||
| CVE-2024-23467 | Cri | 0.63 | 9.6 | 0.03 | Jul 17, 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code execution. | ||
| CVE-2024-23466 | Cri | 0.63 | 9.6 | 0.03 | Jul 17, 2024 | SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. | ||
| CVE-2024-23479 | Cri | 0.63 | 9.6 | 0.06 | Feb 15, 2024 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution. | ||
| CVE-2024-23476 | Cri | 0.63 | 9.6 | 0.07 | Feb 15, 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote Code Execution. | ||
| CVE-2022-36961 | Hig | 0.63 | 8.8 | 0.75 | Sep 30, 2022 | A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution. | ||
| CVE-2021-35215 | Hig | 0.63 | 8.9 | 0.70 | Sep 1, 2021 | Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability. | ||
| CVE-2024-23470 | Cri | 0.62 | 9.6 | 0.01 | Jul 17, 2024 | The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables. | ||
| CVE-2026-28318 | Hig | 0.61 | 7.5 | 0.08 | KEV | Jun 4, 2026 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the… | |
| CVE-2017-6803 | Hig | 0.61 | 8.8 | 0.04 | Mar 20, 2017 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the… |
- risk 0.85cvss 9.8epss 0.84
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
- risk 0.84cvss 9.0epss 0.91
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File…
- risk 0.83cvss 9.8epss 0.88
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which…
- risk 0.83cvss 9.8epss 0.92
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds…
- risk 0.82cvss 9.1epss 0.93
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.
- risk 0.82cvss 9.8epss 0.85
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been…
- risk 0.79cvss 8.6epss 1.00
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
- risk 0.74cvss 8.1epss 0.72
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.
- risk 0.71cvss 9.8epss 0.94
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library.…
- risk 0.71cvss 9.8epss 0.59
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
- risk 0.71cvss 9.8epss 0.51
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.
- risk 0.69cvss 9.8epss 0.60
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
- risk 0.69cvss 10.0epss 0.13
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker…
- risk 0.69cvss 9.8epss 0.70
Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) ScriptSchedule parameter in the…
- risk 0.68cvss 9.8epss 0.57
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.
- risk 0.68cvss 9.8epss 0.50
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.
- risk 0.67cvss 9.8epss 0.39
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous…
- risk 0.67cvss 9.8epss 0.36
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process.…
- risk 0.67cvss 9.8epss 0.36
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The…
- risk 0.66cvss 7.8epss 0.04
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
- risk 0.65cvss 9.0epss 0.78
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing…
- risk 0.65cvss 8.8epss 0.92
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
- risk 0.65cvss 8.8epss 0.66
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
- risk 0.65cvss 9.8epss 0.13
The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
- risk 0.64cvss 9.6epss 0.19
SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.
- risk 0.64cvss 9.6epss 0.18
SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges.
- risk 0.64cvss 8.8epss 0.83
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.64cvss 8.9epss 0.73
Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted…
- risk 0.64cvss 8.9epss 0.76
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server
- risk 0.64cvss 8.9epss 0.81
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
- risk 0.64cvss 9.8epss 0.04
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results…
- risk 0.64cvss 9.8epss 0.01
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
- risk 0.64cvss 9.8epss 0.02
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
- risk 0.64cvss 9.8epss 0.02
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
- risk 0.64cvss 9.8epss 0.07
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
- risk 0.64cvss 9.8epss 0.05
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an…
- risk 0.64cvss 9.8epss 0.03
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
- risk 0.64cvss 9.8epss 0.02
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to…
- risk 0.63cvss 9.6epss 0.11
It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability.
- risk 0.63cvss 9.6epss 0.02
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
- risk 0.63cvss 9.6epss 0.01
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.
- risk 0.63cvss 9.6epss 0.03
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code execution.
- risk 0.63cvss 9.6epss 0.03
SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges.
- risk 0.63cvss 9.6epss 0.06
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.
- risk 0.63cvss 9.6epss 0.07
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote Code Execution.
- risk 0.63cvss 8.8epss 0.75
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.
- risk 0.63cvss 8.9epss 0.70
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.
- risk 0.62cvss 9.6epss 0.01
The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables.
- risk 0.61cvss 7.5epss 0.08
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the…
- risk 0.61cvss 8.8epss 0.04
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the…
Page 1 of 7