CVE-2023-40055: SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability
Published Nov 9, 2023
·Updated
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227
Affected Software
1 affected component
SolarWinds Network Configuration Manager<=2023.4
Remediation
Information
All Network Configuration Manager customers are advised to upgrade to the latest version of the Network Configuration Manager version 2023.4.1
Event History
Nov 9, 2023
CVE Published
03:06 PM
Data Sourced
03:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-40055.
2
What is the title of this vulnerability?
The title of this vulnerability is SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability.
3
What is the severity of CVE-2023-40055?
The severity of CVE-2023-40055 is high.
4
What is the affected software for CVE-2023-40055?
The affected software for CVE-2023-40055 is SolarWinds Network Configuration Manager.
5
How can this vulnerability be exploited?
This vulnerability can be exploited through a Directory Traversal Remote Code Execution attack.