SolarWinds Patches 8 Critical Flaws in Access Rights Manager Software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-23469 | SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. NVD description · AI analysis pending | 8.8 group max | 18% |
| — | ||
| CVE-2024-28995 | Unauthenticated Path Traversal File-Read in SolarWinds Serv-U CVE-2024-28995 is a directory traversal flaw (CWE-22) in SolarWinds Serv-U, the vendor's managed file transfer/FTP server. Per the CVSS vector, it is reachable over the network with low attack complexity and requires no privileges or user interaction, meaning an unauthenticated remote attacker can trigger it. By sending traversal sequences that escape the intended directory, the attacker gains the ability to read sensitive files on the host machine (high confidentiality impact, with no integrity or availability impact). Any organization running SolarWinds Serv-U is potentially affected, particularly instances exposed to the internet. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17, threat actors were reported exploiting it in the wild, and EPSS puts the 30-day exploitation probability at 99.6%, although no public proof-of-concept is known. Do: Apply SolarWinds' patch or hotfix for Serv-U per the vendor's July 2024 PSIRT advisory, prioritizing internet-facing instances; if mitigations cannot be applied, CISA's required action is to follow vendor instructions or discontinue use of the product. In the meantime, restrict Serv-U exposure to trusted networks and review FTP/web server access logs for traversal-style requests that could indicate file reads or exfiltration. | 7.5 | 100% | KEV |
| largelow tens of thousands of internet-exposed Serv-U file-transfer servers |
Full article425 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 19, 2024Vulnerability / Enterprise Security
SolarWinds has addressed a set of critical security flaws impacting its Access Rights Manager (ARM) software that could be exploited to access sensitive information or execute arbitrary code.
Of the 13 vulnerabilities, eight are rated Critical in severity and carry a CVSS score of 9.6 out of 10.0. The remaining five weaknesses have been rated High in severity, with four of them having a CVSS score of 7.6 and one scoring 8.3.
The most severe of the flaws are listed below -
- CVE-2024-23472 - SolarWinds ARM Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability
- CVE-2024-28074 - SolarWinds ARM Internal Deserialization Remote Code Execution Vulnerability
- CVE-2024-23469 - Solarwinds ARM Exposed Dangerous Method Remote Code Execution Vulnerability
- CVE-2024-23475 - Solarwinds ARM Traversal and Information Disclosure Vulnerability
- CVE-2024-23467 - Solarwinds ARM Traversal Remote Code Execution Vulnerability
- CVE-2024-23466 - Solarwinds ARM Directory Traversal Remote Code Execution Vulnerability
- CVE-2024-23470 - Solarwinds ARM UserScriptHumster Exposed Dangerous Method Remote Command Execution Vulnerability
- CVE-2024-23471 - Solarwinds ARM CreateFile Directory Traversal Remote Code Execution Vulnerability
Successful exploitation of the aforementioned vulnerabilities could allow an attacker to read and delete files and execute code with elevated privileges.
The shortcomings have been addressed in version 2024.3 released on July 17, 2024, following responsible disclosure as part of the Trend Micro Zero Day Initiative (ZDI).
The development comes after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed a high-severity path traversal flaw in SolarWinds Serv-U Path (CVE-2024-28995, CVSS score: 8.6) to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.
The network security company was the victim of a major supply chain attack in 2020 after the update mechanism associated with its Orion network management platform was compromised by Russian APT29 hackers to distribute malicious code to downstream customers as part of a high-profile cyber espionage campaign.
The breach prompted the U.S. Securities and Exchange Commission (SEC) to file a lawsuit against SolarWinds and its chief information security officer (CISO) last October alleging the company failed to disclose adequate material information to investors regarding cybersecurity risks.
However, much of the claims pertaining to the lawsuit were thrown out by the U.S. District Court for the Southern District of New York (SDNY) on July 18, stating "these do not plausibly plead actionable deficiencies in the company's reporting of the cybersecurity hack" and that they "impermissibly rely on hindsight and speculation."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/07/solarwinds-patches-11-critical-flaws-in.html