CyberzSOC

Publication detail
← Back to advisories & guidance

2024-097: Vulnerabilities in SolarWinds Access Rights Manager ↗ source

September 16, 2024 CERT-EU Advisory

Summary

These vulnerabilities, if exploited, could lead to authenticated remote code execution, and authentication bypass [1][2]. The vulnerability CVE-2024-28990, with a CVSS Score of 6.3, is a hard-coded credential authentication bypass flaw. If exploited, this vulnerability would allow access to the RabbitMQ The vulnerability CVE-2024-28991, with a CVSS Score of 9.0, is a deserialisation of untrusted data flaw that, if exploited, could lead to remote code execution on the affected server. These vulnerabilities affect SolarWinds Access Rights Manager (ARM) before the version CERT-EU strongly recommends updating software installations to a fixed version [1][2].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-28991 9.0 Critical SolarWinds Access Rights Manager SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would a…
CVE-2024-28990 6.3 Medium SolarWinds Access Rights Manager SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerabi…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.