CVE-2023-40062: Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability
Published Nov 1, 2023
·Updated
SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.
Affected Software
1 affected component
SolarWinds SolarWinds Platform<2023.4
Remediation
Information
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.4
Event History
Nov 1, 2023
CVE Published
03:29 PM
Data Sourced
03:29 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-40062?
CVE-2023-40062 is an Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability in SolarWinds Platform.
2
What is the severity of CVE-2023-40062?
CVE-2023-40062 has a severity level of high with a value of 8.
3
How does CVE-2023-40062 affect the SolarWinds Platform?
CVE-2023-40062 allows a low-privileged user to execute commands with SYSTEM privileges in the SolarWinds Platform.
4
How can I fix CVE-2023-40062?
To fix CVE-2023-40062, it is recommended to apply the latest updates and patches provided by SolarWinds.
5
Where can I find more information about CVE-2023-40062?
You can find more information about CVE-2023-40062 in the SolarWinds release notes and security advisories.