CVE-2024-23472

CRITICAL

SolarWinds Access Rights Manager < 2023.2.4 - Authenticated Path Traversal and Arbitrary File Read/Delete

Title source: llm
STIX 2.1

Description

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.

Scores

CVSS v3 9.6
EPSS 0.0746
EPSS Percentile 91.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
solarwinds/access_rights_manager < 2023.2.4
Published Jul 17, 2024
Tracked Since Feb 18, 2026