CVE-2024-23478: SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Access Rights Manager (ARM)to a version that resolves this vulnerability.Fixed in 2023.2.3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-23478?
CVE-2024-23478 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-23478?
To mitigate CVE-2024-23478, update SolarWinds Access Rights Manager to version 2023.2.4 or later.
Who is affected by CVE-2024-23478?
CVE-2024-23478 primarily affects users of SolarWinds Access Rights Manager version 2023.2.3.
What type of vulnerability is CVE-2024-23478?
CVE-2024-23478 is a Remote Code Execution vulnerability that can be exploited by authenticated users.
Can CVE-2024-23478 be exploited without authentication?
No, CVE-2024-23478 requires authentication to exploit the vulnerability.