Vulnerabilities > Solarwinds

DATE CVE VULNERABILITY TITLE RISK
2019-06-17 CVE-2019-12181 OS Command Injection vulnerability in Solarwinds Serv-U FTP Server and Serv-U MFT Server
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
network
low complexity
solarwinds CWE-78
8.8
2019-06-07 CVE-2019-3957 Out-of-bounds Read vulnerability in Solarwinds Dameware Mini Remote Control
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
5.8
2019-06-07 CVE-2018-19999 Improper Authentication vulnerability in Solarwinds Serv-U FTP Server 15.1.6.25
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation.
local
low complexity
solarwinds CWE-287
7.2
2019-05-02 CVE-2019-9017 Out-of-bounds Write vulnerability in Solarwinds Dameware Mini Remote Control 10.0
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
network
low complexity
solarwinds CWE-787
7.5
2019-03-21 CVE-2018-19934 Cross-site Scripting vulnerability in Solarwinds Serv-U FTP Server 15.1.6.25
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
network
solarwinds CWE-79
3.5
2019-03-21 CVE-2018-15906 Unspecified vulnerability in Solarwinds Serv-U FTP Server 15.1.6
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
network
low complexity
solarwinds
critical
9.0
2019-03-01 CVE-2019-9546 Uncontrolled Search Path Element vulnerability in Solarwinds Orion Platform
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
network
low complexity
solarwinds CWE-427
7.5
2019-02-18 CVE-2019-8917 Unspecified vulnerability in Solarwinds Orion Network Performance Monitor
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service.
network
low complexity
solarwinds
critical
10.0
2018-12-05 CVE-2018-16792 XXE vulnerability in Solarwinds Sftp/Scp Server 20180910
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
network
low complexity
solarwinds CWE-611
6.4
2018-12-05 CVE-2018-16791 Insufficiently Protected Credentials vulnerability in Solarwinds Sftp/Scp Server
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts.
network
low complexity
solarwinds CWE-522
5.0