CVE-2019-8917: Critical severity solarwinds network performance monitor vulnerability
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-8917?
CVE-2019-8917 is a remote code execution vulnerability in SolarWinds Orion NPM before version 12.4.
What is the severity of CVE-2019-8917?
The severity of CVE-2019-8917 is critical with a CVSS score of 9.8.
How does CVE-2019-8917 affect SolarWinds Orion NPM?
CVE-2019-8917 allows remote, unauthenticated clients to execute arbitrary code on systems running SolarWinds Orion NPM before version 12.4.
Is there a fix available for CVE-2019-8917?
Yes, the vulnerability can be fixed by upgrading SolarWinds Orion NPM to version 12.4 or newer.
Where can I find more information about CVE-2019-8917?
More information about CVE-2019-8917 can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/107061) and [VerSprite Research Advisory](https://github.com/VerSprite/research/blob/master/advisories/VS-2019-001.md).