CVE-2023-40057: SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution
Published Feb 15, 2024
·Updated
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.
Affected Software
5 affected components
SolarWinds Access Rights Manager<2023.2.2
SolarWinds Access Rights Manager=2023.2.3
JetBrains TeamCity
SonicWall firewall
Perforce Helix Core Server
Remediation
Information
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2023.2.3
Event History
Feb 15, 2024
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
RemedyDescriptionSeverityWeakness
Feb 16, 2024
News Published
via BleepingComputer·06:32 PM
News Published
via BleepingComputer·06:33 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2023-40057?
CVE-2023-40057 is classified as a critical remote code execution vulnerability.
2
How do I fix CVE-2023-40057?
To fix CVE-2023-40057, upgrade the SolarWinds Access Rights Manager to version 2023.2.3 or later.
3
Who is affected by CVE-2023-40057?
CVE-2023-40057 affects users of SolarWinds Access Rights Manager version 2023.2.2 and earlier.
4
What can an attacker do with CVE-2023-40057?
An attacker exploiting CVE-2023-40057 can execute arbitrary code remotely on the affected system.
5
Is CVE-2023-40057 easy to exploit?
CVE-2023-40057 requires authenticated access, which may limit the attack surface.