First published: Thu Oct 19 2023(Updated: )
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Access Rights Manager | <=2023.2.0.73 |
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-35184.
The severity of CVE-2023-35184 is critical with a CVSS score of 9.8.
The SolarWinds Access Rights Manager version 2023.2.0.73 is affected by CVE-2023-35184.
An unauthenticated user can abuse the SolarWinds service to perform remote code execution.
Yes, you can find references for CVE-2023-35184 at the following URLs: - https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm - https://www.solarwinds.com/trust-center/security-advisories/CVE-2023-35184