First published: Wed Nov 01 2023(Updated: )
SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
Solarwinds Solarwinds Platform | <2023.4 |
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.4
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40062 is an Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability in SolarWinds Platform.
CVE-2023-40062 has a severity level of high with a value of 8.
CVE-2023-40062 allows a low-privileged user to execute commands with SYSTEM privileges in the SolarWinds Platform.
To fix CVE-2023-40062, it is recommended to apply the latest updates and patches provided by SolarWinds.
You can find more information about CVE-2023-40062 in the SolarWinds release notes and security advisories.