CVE-2023-23845

MEDIUM

SolarWinds Platform - Privilege Escalation

Title source: llm
STIX 2.1

Description

The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

Scores

CVSS v3 6.8
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-697
Status published
Products (1)
solarwinds/orion_platform < 2023.3.1
Published Sep 13, 2023
Tracked Since Feb 18, 2026