CVE-2024-28991

CRITICAL

Solarwinds Access Rights Manager < 2024.3.1 - Insecure Deserialization

Title source: rule

Description

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

Scores

CVSS v3 9.0
EPSS 0.3090
EPSS Percentile 96.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

solarwinds/access_rights_manager < 2024.3.1

Timeline

Published Sep 12, 2024
Tracked Since Feb 18, 2026