ZDI-CAN-21223: ZDI-23-1585: SolarWinds Network Configuration Manager ExportConfigs Directory Traversal Remote Code Execution Vulnerability
Published Nov 6, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Configuration Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-33226.
Affected Software
1 affected component
SolarWinds Network Configuration Manager
Event History
Nov 6, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21223?
The severity of ZDI-CAN-21223 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-CAN-21223?
To fix ZDI-CAN-21223, you should apply the latest security patch provided by SolarWinds for the Network Configuration Manager.
3
What type of attacks can exploit ZDI-CAN-21223?
ZDI-CAN-21223 can be exploited by remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-CAN-21223?
Yes, authentication is required to successfully exploit ZDI-CAN-21223.
5
What software is affected by ZDI-CAN-21223?
ZDI-CAN-21223 affects installations of SolarWinds Network Configuration Manager.