CVE-2024-28991
CRITICALSolarwinds Access Rights Manager < 2024.3.1 - Insecure Deserialization
Title source: ruleDescription
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.
Scores
CVSS v3
9.0
EPSS
0.3090
EPSS Percentile
96.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
solarwinds/access_rights_manager
< 2024.3.1
Timeline
Published
Sep 12, 2024
Tracked Since
Feb 18, 2026