SolarWinds Security Updates – 21 September 2023

SolarWinds has released security updates to fix multiple vulnerabilities in the SolarWinds Platform 2023.3 and prior versions.

The addressed vulnerabilities could allow the remote attacker to execute arbitrary commands with NETWORK SERVICE privileges on the affected system.

The addressed vulnerabilities:

1. SolarWinds Platform Command Execution Vulnerability (CVE-2023-23840):

  • CVSS: 6.8
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access

2. SolarWinds Platform Command Execution Vulnerability (CVE-2023-23845):

  • CVSS: 6.8
  • Attack Vector: Adjacent Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2023-23840
  • CVE-2023-23845
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security advisory

References