ZDI-CAN-21095: ZDI-23-1004: SolarWinds Orion Platform BlacklistedFilesChecker Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability
Published Jul 27, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Platform. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
SolarWinds Orion Platform
Event History
Jul 27, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21095?
The severity of ZDI-CAN-21095 is high due to its potential for remote code execution on affected systems.
2
How do I fix ZDI-CAN-21095?
To fix ZDI-CAN-21095, apply the latest security patches provided by SolarWinds for the Orion Platform.
3
Who is affected by ZDI-CAN-21095?
Organizations using the SolarWinds Orion Platform are affected by ZDI-CAN-21095.
4
What type of vulnerability is ZDI-CAN-21095?
ZDI-CAN-21095 is a remote code execution vulnerability that requires authentication to exploit.
5
Can ZDI-CAN-21095 be exploited without authentication?
No, ZDI-CAN-21095 cannot be exploited without proper authentication.