CVE-2023-33225

HIGH

SolarWinds Platform - Privilege Escalation

Title source: llm
STIX 2.1

Description

The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.

Scores

CVSS v3 7.2
EPSS 0.0010
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-697
Status published
Products (1)
solarwinds/solarwinds_platform < 2023.3.0
Published Jul 26, 2023
Tracked Since Feb 18, 2026