SolarWinds Security Update – 05 March 2024

SolarWinds has released a security update to address a vulnerability affectingSolarWinds SEM 2023.4 and prior ersions.

The addressed vulnerability could allow the attacker to execute arbitrary code and gain access to the affected system.

SolarWinds Security Event Manager Remote Code Execution Vulnerability (CVE-2024-0692):

  • CVSS: 8.8
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-0692

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Advisory

References