ZDI-23-168: SolarWinds Network Performance Monitor sshd_SftpRename Directory Traversal Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication may be required to exploit this vulnerability, depending on the product configuration.
Affected Software
1 affected component
SolarWinds Network Performance Monitor
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-168?
The severity of ZDI-23-168 is high due to its ability to allow remote code execution.
2
How do I fix ZDI-23-168?
To fix ZDI-23-168, apply the latest security patches provided by SolarWinds for the Network Performance Monitor.
3
Who can exploit ZDI-23-168?
Both authenticated and unauthenticated attackers may exploit ZDI-23-168, depending on the configuration of the product.
4
What software is affected by ZDI-23-168?
ZDI-23-168 affects installations of SolarWinds Network Performance Monitor.
5
Is authentication required to exploit ZDI-23-168?
Authentication may be required for exploiting ZDI-23-168 depending on the specific product configuration.