The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.
We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.4
Workaround
No workaround given by the vendor.
References
History
Mon, 10 Feb 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solarwinds
Solarwinds access Rights Manager |
|
| CPEs | cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Solarwinds
Solarwinds access Rights Manager |
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2024-08-02T00:48:48.249Z
Reserved: 2024-03-01T08:53:44.513Z
Link: CVE-2024-28075
Updated: 2024-08-02T00:48:48.249Z
Status : Analyzed
Published: 2024-05-14T15:13:53.397
Modified: 2025-02-10T22:49:58.503
Link: CVE-2024-28075
No data.
OpenCVE Enrichment
No data.