First published: Wed Jul 17 2024(Updated: )
The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin access within the Active Directory environment.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Access Rights Manager | <=2023.2.4 |
All SolarWinds Access Rights Manager customers are advised to upgrade to the latest version of the SolarWinds Access Rights Manager 2024.3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23465 is considered a critical vulnerability as it allows unauthenticated users to gain domain admin access.
To fix CVE-2024-23465, upgrade the SolarWinds Access Rights Manager to version 2023.2.5 or later.
CVE-2024-23465 affects all versions of SolarWinds Access Rights Manager up to and including version 2023.2.4.
CVE-2024-23465 is categorized as an authentication bypass vulnerability.
No, CVE-2024-23465 can be exploited by unauthenticated users only.