Vulnerabilities > Solarwinds

DATE CVE VULNERABILITY TITLE RISK
2023-10-19 CVE-2023-35183 Incorrect Default Permissions vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability.
local
low complexity
solarwinds CWE-276
7.8
2023-10-19 CVE-2023-35184 Deserialization of Untrusted Data vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability.
network
low complexity
solarwinds CWE-502
critical
9.8
2023-10-19 CVE-2023-35185 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges.
low complexity
solarwinds CWE-22
6.8
2023-10-19 CVE-2023-35186 Deserialization of Untrusted Data vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability.
network
low complexity
solarwinds CWE-502
8.8
2023-10-19 CVE-2023-35187 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability.
network
low complexity
solarwinds CWE-22
critical
9.8
2023-09-13 CVE-2023-23840 Incorrect Comparison vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability.
network
low complexity
solarwinds CWE-697
7.2
2023-09-13 CVE-2023-23845 Incorrect Comparison vulnerability in Solarwinds Orion Platform
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability.
network
low complexity
solarwinds CWE-697
7.2
2023-09-07 CVE-2023-40060 Improper Access Control vulnerability in Solarwinds Serv-U 15.4.0
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication.
network
low complexity
solarwinds CWE-284
7.2
2023-08-11 CVE-2023-35179 Improper Access Control vulnerability in Solarwinds Serv-U 15.4.0
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication.
network
low complexity
solarwinds CWE-284
7.2
2023-07-26 CVE-2023-23842 Path Traversal vulnerability in Solarwinds Network Configuration Monitor
The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability.
network
low complexity
solarwinds CWE-22
7.2