← back
CVE-2023-23842

SolarWinds Network Configuration Manager Directory Traversal Vulnerability

CVSS 7.2 HIGHEPSS 3.3%CWE-22
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 3.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
26 Jul 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →