ZDI-CAN-19776: ZDI-23-166: SolarWinds Network Performance Monitor SqlFileScript Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Network Performance Monitor
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19776?
The severity of ZDI-CAN-19776 is critical, as it allows remote attackers to execute arbitrary code.
2
How do I fix ZDI-CAN-19776?
To fix ZDI-CAN-19776, ensure all affected installations of SolarWinds Network Performance Monitor are updated to the latest version.
3
Is authentication required to exploit ZDI-CAN-19776?
Yes, successful exploitation of ZDI-CAN-19776 requires authentication.
4
What types of systems are affected by ZDI-CAN-19776?
ZDI-CAN-19776 affects installations of SolarWinds Network Performance Monitor.
5
Can ZDI-CAN-19776 lead to data breaches?
Yes, if exploited, ZDI-CAN-19776 could potentially lead to unauthorized data access and breaches.