CVE-2022-38108: SolarWinds Network Performance Monitor BytesToMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability. The specific flaw exists within the MessageToBytes function. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-38108?
CVE-2022-38108 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor.
Does CVE-2022-38108 require authentication to exploit?
Yes, authentication is required to exploit CVE-2022-38108.
What is the severity of CVE-2022-38108?
CVE-2022-38108 has a severity value of 7.2 (High).
What software is affected by CVE-2022-38108?
CVE-2022-38108 affects SolarWinds Network Performance Monitor version 2020.2.6 and versions 2022.2 and 2022.3 of SolarWinds Orion Platform.
How do I fix CVE-2022-38108?
To fix CVE-2022-38108, it is recommended to apply the necessary security patches provided by SolarWinds.