PT-2023-2270 · Solarwinds · Solarwinds Server/Application Monitor

Published

2023-02-15

·

Updated

2023-02-24

·

CVE-2022-47508

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Solarwinds Server & Application Monitor (affected versions not specified)
Description The issue is related to weaknesses in the authentication procedure, allowing a remote attacker to bypass authentication and access confidential information using specially crafted NTLM protocol messages. Customers who configured polling via Kerberos did not expect NTLM traffic, but querying data via IP address prevented the use of Kerberos.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-02031
CVE-2022-47508

Affected Products

Solarwinds Server/Application Monitor