ZDI-CAN-22681: ZDI-24-908: SolarWinds Access Rights Manager Connect Method Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Access Rights Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2024-23466.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22681?
ZDI-CAN-22681 has a CVSS rating of 10.0, indicating it is a critical vulnerability.
How do I fix ZDI-CAN-22681?
To fix ZDI-CAN-22681, you should apply the latest security patches provided by SolarWinds for Access Rights Manager.
Which versions of SolarWinds Access Rights Manager are affected by ZDI-CAN-22681?
ZDI-CAN-22681 affects all installations of SolarWinds Access Rights Manager that are not updated with the security patches.
Can ZDI-CAN-22681 be exploited without authentication?
Yes, ZDI-CAN-22681 can be exploited without requiring any authentication.
What type of attack does ZDI-CAN-22681 enable?
ZDI-CAN-22681 allows remote attackers to execute arbitrary code on the affected systems.