9
CVE-2024-28991
- EPSS 30.9%
- Veröffentlicht 12.09.2024 14:16:06
- Zuletzt bearbeitet 16.09.2024 18:06:20
- Quelle psirt@solarwinds.com
- CVE-Watchlists
- Unerledigt
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Solarwinds ≫ Access Rights Manager Version < 2024.3.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 30.9% | 0.966 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@solarwinds.com | 9 | 2.3 | 6 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.