ZDI-23-1585: SolarWinds Network Configuration Manager ExportConfigs Directory Traversal Remote Code Execution Vulnerability
Published Nov 6, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Configuration Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-33226.
Affected Software
1 affected component
SolarWinds Network Configuration Manager
Event History
Nov 6, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1585?
The severity of ZDI-23-1585 is rated 8.8 on the CVSS scale, indicating a high level of risk.
2
How do I fix ZDI-23-1585?
To fix ZDI-23-1585, apply the latest security patches released by SolarWinds for Network Configuration Manager.
3
What are the consequences of exploiting ZDI-23-1585?
Exploiting ZDI-23-1585 allows remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-23-1585?
Yes, authentication is required to exploit the ZDI-23-1585 vulnerability.
5
What software is affected by ZDI-23-1585?
ZDI-23-1585 affects installations of SolarWinds Network Configuration Manager.