CVE-2023-35180: SolarWinds Access Rights Manager Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Oct 19, 2023
·Updated
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse SolarWinds ARM API.
Affected Software
1 affected component
SolarWinds Access Rights Manager<=2023.2.0.73
Remediation
Information
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.1
Event History
Oct 19, 2023
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
RemedyDescriptionSeverityWeakness
Data Sourced
03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the SolarWinds Access Rights Manager vulnerability?
The vulnerability ID of the SolarWinds Access Rights Manager vulnerability is CVE-2023-35180.
2
What is the severity of CVE-2023-35180?
CVE-2023-35180 has a severity rating of high.
3
How does the SolarWinds Access Rights Manager vulnerability allow remote code execution?
The vulnerability allows authenticated users to abuse SolarWinds ARM API, leading to remote code execution.
4
What version of SolarWinds Access Rights Manager is affected by CVE-2023-35180?
SolarWinds Access Rights Manager versions up to (and inclusive of) 2023.2.0.73 are affected.
5
How can I mitigate the SolarWinds Access Rights Manager vulnerability?
To mitigate the vulnerability, it is recommended to update SolarWinds Access Rights Manager to a version that includes the security patch.