PT-2023-2039 · Solarwinds · Solarwinds Orion

Chudypb

+1

·

Published

2023-02-15

·

Updated

2023-08-03

·

CVE-2022-47503

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SolarWinds Orion (affected versions not specified)
Description The issue is related to the deserialization of untrusted data, which can allow a remote adversary with admin-level account access to the SolarWinds Web Console to execute arbitrary commands. This can be exploited by an attacker to gain unauthorized access and control.
Recommendations As a temporary workaround, consider restricting access to the SolarWinds Web Console to minimize the risk of exploitation. Restrict access to admin-level accounts in the SolarWinds Web Console until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-01756
CVE-2022-47503
ZDI-23-213

Affected Products

Solarwinds Orion