SolarWinds Vulnerabilities and Affected Products
Vulnerabilities associated with solarwinds_platform.
Products
Clear product- SolarWinds Platform41 vulnerabilities
- Serv-U37 vulnerabilities
- Access Rights Manager32 vulnerabilities
- Orion Platform24 vulnerabilities
- access_rights_manager23 vulnerabilities
- Web Help Desk19 vulnerabilities
- solarwinds_platform8 vulnerabilities
- Network Configuration Manager7 vulnerabilities
- SolarWinds Observability Self-Hosted7 vulnerabilities
- Kiwi Syslog Server5 vulnerabilities
- Database Performance Analyzer4 vulnerabilities
- webhelpdesk4 vulnerabilities
- Orion3 vulnerabilities
- Patch Manager3 vulnerabilities
- SolarWinds SEM3 vulnerabilities
- Database Performance Analyzer (DPA)2 vulnerabilities
- Kiwi CatTools2 vulnerabilities
- Network Performance Monitor2 vulnerabilities
- Observability Self-Hosted2 vulnerabilities
- ServU2 vulnerabilities
- SolarWinds2 vulnerabilities
- Dameware Mini Remote Control Service1 vulnerability
- dameware_mini_remote_control1 vulnerability
- Database Performance Monitor1 vulnerability
- DPA1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-45710HIGH | SolarWinds Platform Uncontrolled Search Path Element Local Privilege Escalation VulnerabilitySolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine. CWE-427Oct 16, 2024 | CVSS7.8v3.1 | EPSS0.278% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29004HIGH | SolarWinds Platform Stored XSS VulnerabilityThe SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability. CWE-79Jun 4, 2024 | CVSS7.1v3.1 | EPSS0.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28999MEDIUM | SolarWinds Platform Race Condition VulnerabilityThe SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. CWE-362Jun 4, 2024 | CVSS6.4v3.1 | EPSS13.9% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28996HIGH | SolarWinds Platform SWQL Injection VulnerabilityThe SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability. CWE-89Jun 4, 2024 | CVSS7.5v3.1 | EPSS0.349% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29000HIGH | SolarWinds Platform Reflected XSS VulnerabilityThe SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability. CWE-79May 20, 2024 | CVSS7.9v3.1 | EPSS0.463% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29003HIGH | SolarWinds Platform Cross Site Scripting VulnerabilityThe SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction. CWE-79Apr 18, 2024 | CVSS7.5v3.1 | EPSS0.696% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29001HIGH | SolarWinds Platform SWQL Injection VulnerabilityA SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited. CWE-89Apr 18, 2024 | CVSS7.5v3.1 | EPSS0.59% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-28076HIGH | SolarWinds Platform Arbitrary Open Redirection VulnerabilityThe SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format CWE-601Apr 18, 2024 | CVSS7.0v3.1 | EPSS0.341% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |