documentation.solarwinds.comrelease notes
https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2024-2_release_notes.htm CVE-2024-28999
MEDIUM
SolarWinds Platform Race Condition Vulnerability
Record summary
CVE-2024-28999 has a selected CVSS score of 6.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SolarWinds PlatformBrowse SolarWinds / SolarWinds PlatformDefault status: affected, unknown | CVE List | 2024.1.1 and previous versions | affected |
| Through 2024.1 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBSolarWinds Platform 2024.1 SR1 - Race ConditionExploitDB exploitby Elhussain FathyNot analyzed1 file
Repository PoCs
GitHubHussainFathy/CVE-2024-28999Repository PoCby HussainFathyStars: 4Not analyzed2 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-28999 solarwinds.comVendor advisory
https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28999