ZDI-CAN-20995: ZDI-23-1002: SolarWinds Network Configuration Manager VulnDownloader Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Configuration Manager. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20995?
The ZDI-CAN-20995 vulnerability is considered critical due to the potential for remote code execution.
How do I fix ZDI-CAN-20995?
To mitigate ZDI-CAN-20995, apply the latest security patches provided by SolarWinds for Network Configuration Manager.
What are the prerequisites to exploit ZDI-CAN-20995?
Exploitation of ZDI-CAN-20995 requires authentication to the affected SolarWinds Network Configuration Manager system.
What types of systems are affected by ZDI-CAN-20995?
ZDI-CAN-20995 affects installations of SolarWinds Network Configuration Manager that meet certain conditions.
Can ZDI-CAN-20995 be exploited without access?
No, the ZDI-CAN-20995 vulnerability cannot be exploited without valid authentication to the affected system.