PT-2017-19004 · Solarwinds · Solarwinds Network Performance Monitor

Published

2017-10-02

·

Updated

2018-10-09

·

CVE-2017-9538

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Network Performance Monitor version 12.0.15300.90
Description The issue is related to the 'Upload logo from external path' function, which allows remote attackers to cause a denial of service. This denial of service results in a permanent display of a "Cannot exit above the top directory" error message throughout the entire web application. The cause of the denial of service is an incorrect implementation of a directory-traversal protection mechanism, specifically when a ".." is used in the path field.
Recommendations For SolarWinds Network Performance Monitor version 12.0.15300.90, consider disabling the 'Upload logo from external path' function as a temporary workaround until a patch is available. Restrict access to this function to minimize the risk of exploitation. Avoid using the ".." in the path field in the affected function until the issue is resolved.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9538

Affected Products

Solarwinds Network Performance Monitor