First published: Thu Oct 19 2023(Updated: )
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.
Credit: psirt@solarwinds.com psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Access Rights Manager | <=2023.2.0.73 |
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35186 is a vulnerability that allows an authenticated user to abuse SolarWinds Access Rights Manager service, resulting in remote code execution.
CVE-2023-35186 has a severity level of high, with a severity value of 8.
An attacker can exploit CVE-2023-35186 by abusing the SolarWinds Access Rights Manager service, which allows for remote code execution.
Yes, a fix is available for CVE-2023-35186. It is recommended to update to SolarWinds Access Rights Manager version 2023.2.1 or later.
You can find more information about CVE-2023-35186 in the SolarWinds documentation and security advisories.