First published: Wed Sep 13 2023(Updated: )
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
<2023.3.1 | ||
SolarWinds Orion Platform | <2023.3.1 |
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.3.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23840 refers to the Incorrect Comparison Vulnerability present in the SolarWinds Platform.
CVE-2023-23840 allows users with administrative access to the SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
CVE-2023-23840 has a severity rating of 7.2 (high).
The SolarWinds Orion Platform up to version 2023.3.1 is affected by CVE-2023-23840.
You can find more information about CVE-2023-23840 in the SolarWinds documentation and security advisory.