CyberzSOC

Publication detail
← Back to advisories & guidance

2024-071: Critical Vulnerabilities in SolarWinds Access Rights Manager ↗ source

July 19, 2024 CERT-EU Advisory

Summary

These vulnerabilities could lead to remote code execution, arbitrary file deletion and sensitive information leakage. The vulnerabilities CVE-2024-23469, CVE-2024-23466, CVE-2024-23467, CVE-2024-28074, CVE-2024-23471, and CVE-2024-23470, all with a CVSS score of 9.6, could lead to remote code execution if exploited. ThevulnerabilitiesCVE-2024-23475,andCVE-2024-23472,bothwithaCVSSscoreof9.6,are directory traversal and sensitive information disclosure flaws. The vulnerability CVE-2024-23465, with a CVSS score of 8.3, is an authentication bypass vulnerability. CERT-EU recommends updating affected devices to the latest version of SolarWinds Access Rights Manager as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-23466 9.6 Critical SolarWinds Access Rights Manager SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability …
CVE-2024-23467 9.6 Critical SolarWinds Access Rights Manager The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …
CVE-2024-23469 9.6 Critical SolarWinds Access Rights Manager SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenti…
CVE-2024-23470 9.6 Critical SolarWinds Access Rights Manager The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vuln…
CVE-2024-23471 9.6 Critical SolarWinds Access Rights Manager The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an…
CVE-2024-23472 9.6 Critical SolarWinds Access Rights Manager SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitr…
CVE-2024-23475 9.6 Critical SolarWinds Access Rights Manager The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …
CVE-2024-28074 9.6 Critical SolarWinds Access Rights Manager It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented …
CVE-2024-23465 8.3 High SolarWinds Access Rights Manager The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthentica…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.