SolarWinds Platform是美国SolarWinds公司的一个统一监控、可观察性和服务管理平台。 SolarWinds Platform 2023.3之前版本存在安全漏洞,该漏洞源于容易受到不正确行为顺序的影响,允许具有 SolarWinds Web Console 管理访问权限的用户以 NETWORK SERVICE 权限执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SolarWinds | SolarWinds Platform | 0 ~ 2023.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-23844 | 7.2 HIGH | SolarWinds Platform Incomplete List of Disallowed Inputs Vulnerability |
| CVE-2023-33225 | 7.2 HIGH | SolarWinds Platform Deserialization of Untrusted Data Vulnerability |
| CVE-2023-23843 | 7.2 HIGH | SolarWinds Platform Incorrect Comparison Vulnerability |
| CVE-2023-23842 | 7.2 HIGH | SolarWinds Network Configuration Manager Directory Traversal Vulnerability |
| CVE-2023-33229 | 3.5 LOW | SolarWinds Platform Incorrect Input Neutralization Vulnerability |
No comments yet