PT-2023-2039 · Solarwinds · Solarwinds Orion

·

CVE-2022-47503

·

Publicado

2023-02-15

·

Atualizado

2023-08-03

CVSS v2.0

8.3

Alta

VetorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SolarWinds Orion (affected versions not specified)
Description The issue is related to the deserialization of untrusted data, which can allow a remote adversary with admin-level account access to the SolarWinds Web Console to execute arbitrary commands. This can be exploited by an attacker to gain unauthorized access and control.
Recommendations As a temporary workaround, consider restricting access to the SolarWinds Web Console to minimize the risk of exploitation. Restrict access to admin-level accounts in the SolarWinds Web Console until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-01756
CVE-2022-47503
ZDI-23-213

Produtos afetados

Solarwinds Orion