ZDI-CAN-19648: ZDI-23-167: SolarWinds Orion Platform BytesToMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Orion Platform
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19648?
ZDI-CAN-19648 is a high severity vulnerability that allows remote code execution on affected SolarWinds Orion Platform installations.
2
How do I fix ZDI-CAN-19648?
To fix ZDI-CAN-19648, ensure that you apply the latest security patch provided by SolarWinds for the Orion Platform.
3
What systems are affected by ZDI-CAN-19648?
ZDI-CAN-19648 affects affected installations of the SolarWinds Orion Platform.
4
Is authentication required to exploit ZDI-CAN-19648?
Yes, authentication is required to successfully exploit the ZDI-CAN-19648 vulnerability.
5
What type of attacks can ZDI-CAN-19648 facilitate?
ZDI-CAN-19648 allows remote attackers to execute arbitrary code on the affected SolarWinds Orion Platform.