CVE-2023-33224

HIGH

SolarWinds Platform - Privilege Escalation

Title source: llm
STIX 2.1

Description

The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

Scores

CVSS v3 7.2
EPSS 0.0025
EPSS Percentile 48.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-696
Status published
Products (1)
solarwinds/solarwinds_platform < 2023.3.0
Published Jul 26, 2023
Tracked Since Feb 18, 2026