CVE-2024-23470: SolarWinds Access Rights Manager (ARM) UserScriptHumster Exposed Dangerous Method Remote Command Execution Vulnerability
The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23470?
CVE-2024-23470 is classified as a critical severity vulnerability due to its potential for pre-authentication remote code execution.
How do I fix CVE-2024-23470?
To fix CVE-2024-23470, it is essential to update the SolarWinds Access Rights Manager to version 2024.3 or later.
What are the consequences of exploiting CVE-2024-23470?
Exploitation of CVE-2024-23470 allows an unauthenticated user to execute arbitrary commands on the affected system.
Which versions of SolarWinds Access Rights Manager are affected by CVE-2024-23470?
CVE-2024-23470 affects all versions of SolarWinds Access Rights Manager up to and including 2023.2.4.
Is there a workaround for CVE-2024-23470 if I cannot immediately update?
Currently, there is no documented workaround for CVE-2024-23470, so the recommended action is to apply the security update as soon as possible.