ZDI-CAN-20161: ZDI-23-170: SolarWinds Network Performance Monitor CredentialInitializer Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20161?
The severity of ZDI-CAN-20161 is critical due to the potential for remote code execution by authenticated attackers.
How do I fix ZDI-CAN-20161?
To fix ZDI-CAN-20161, ensure that you update to the latest version of SolarWinds Network Performance Monitor that addresses the vulnerability.
What affects my system if ZDI-CAN-20161 is exploited?
If ZDI-CAN-20161 is exploited, attackers can execute arbitrary code on your SolarWinds Network Performance Monitor installation.
Who is impacted by ZDI-CAN-20161?
Organizations using affected installations of SolarWinds Network Performance Monitor with valid credentials are impacted by ZDI-CAN-20161.
Is authentication required to exploit ZDI-CAN-20161?
Yes, authentication is required to exploit ZDI-CAN-20161.