ZDI-23-457: SolarWinds Network Performance Monitor ExecuteExternalProgram Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-457?
The severity of ZDI-23-457 is critical due to its ability to allow remote code execution.
How do I fix ZDI-23-457?
To fix ZDI-23-457, ensure that you update SolarWinds Network Performance Monitor to the latest patched version.
Who is affected by ZDI-23-457?
ZDI-23-457 affects installations of SolarWinds Network Performance Monitor that are vulnerable to remote code execution.
What type of authentication is needed to exploit ZDI-23-457?
Exploitation of ZDI-23-457 requires authenticated access to the affected SolarWinds Network Performance Monitor instances.
What are the consequences of ZDI-23-457 being exploited?
Exploiting ZDI-23-457 can lead to unauthorized remote code execution, potentially compromising the entire network monitored by the software.