ZDI-23-170: SolarWinds Network Performance Monitor CredentialInitializer Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Network Performance Monitor
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-170?
The severity of ZDI-23-170 is high due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix ZDI-23-170?
To fix ZDI-23-170, ensure that your SolarWinds Network Performance Monitor is updated to the latest patched version.
3
What impact does ZDI-23-170 have on my system?
ZDI-23-170 can lead to unauthorized remote code execution, compromising the integrity and security of your system.
4
Is authentication required to exploit ZDI-23-170?
Yes, authentication is required to exploit ZDI-23-170, making it critical to secure user access.
5
What versions of SolarWinds are affected by ZDI-23-170?
ZDI-23-170 affects installations of SolarWinds Network Performance Monitor that have not been updated.