CVE-2024-23474

HIGH

SolarWinds Access Rights Manager < 2023.2.4 - Arbitrary File Deletion and Information Disclosure

Title source: llm
STIX 2.1

Description

The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.

Scores

CVSS v3 7.6
EPSS 0.0006
EPSS Percentile 19.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
solarwinds/access_rights_manager < 2023.2.4
Published Jul 17, 2024
Tracked Since Feb 18, 2026