Filtered by vendor Solarwinds
Subscriptions
Total
253 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-35252 | 1 Solarwinds | 1 Serv-u | 2023-10-23 | 7.5 High |
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext. | ||||
CVE-2021-35246 | 1 Solarwinds | 1 Engineer\'s Toolset | 2023-10-23 | 5.3 Medium |
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users. | ||||
CVE-2019-9017 | 1 Solarwinds | 1 Dameware Mini Remote Control | 2023-09-25 | 7.5 High |
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name. | ||||
CVE-2023-40060 | 1 Solarwinds | 1 Serv-u | 2023-09-14 | 7.2 High |
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4. SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1. | ||||
CVE-2023-35179 | 1 Solarwinds | 1 Serv-u | 2023-09-14 | 7.2 High |
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. | ||||
CVE-2022-38112 | 1 Solarwinds | 1 Database Performance Analyzer | 2023-09-14 | 7.5 High |
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | ||||
CVE-2021-35211 | 1 Solarwinds | 1 Serv-u | 2023-08-08 | 10.0 Critical |
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability. | ||||
CVE-2023-33231 | 1 Solarwinds | 1 Database Performance Analyzer | 2023-08-03 | 6.1 Medium |
XSS attack was possible in DPA 2023.2 due to insufficient input validation | ||||
CVE-2023-33224 | 1 Solarwinds | 1 Solarwinds Platform | 2023-08-03 | 7.2 High |
The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges. | ||||
CVE-2023-23844 | 1 Solarwinds | 1 Solarwinds Platform | 2023-08-03 | 7.2 High |
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges. | ||||
CVE-2023-23843 | 1 Solarwinds | 1 Solarwinds Platform | 2023-08-03 | 7.2 High |
The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands. | ||||
CVE-2023-23839 | 1 Solarwinds | 1 Solarwinds Platform | 2023-08-03 | 6.5 Medium |
The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information. | ||||
CVE-2023-23838 | 2 Microsoft, Solarwinds | 2 Windows, Database Performance Analyzer | 2023-08-03 | 6.5 Medium |
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | ||||
CVE-2023-23837 | 2 Microsoft, Solarwinds | 2 Windows, Database Performance Analyzer | 2023-08-03 | 7.5 High |
No exception handling vulnerability which revealed sensitive or excessive information to users. | ||||
CVE-2023-23836 | 1 Solarwinds | 1 Orion Platform | 2023-08-03 | 7.2 High |
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands. | ||||
CVE-2022-47512 | 2 Microsoft, Solarwinds | 2 Windows, Solarwinds Platform | 2023-08-03 | 5.5 Medium |
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected | ||||
CVE-2022-47509 | 1 Solarwinds | 1 Orion Platform | 2023-08-03 | 6.1 Medium |
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML. | ||||
CVE-2022-47507 | 1 Solarwinds | 1 Orion Platform | 2023-08-03 | 7.2 High |
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | ||||
CVE-2022-47506 | 1 Solarwinds | 1 Orion Platform | 2023-08-03 | 7.8 High |
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands. | ||||
CVE-2022-47505 | 1 Solarwinds | 1 Orion Platform | 2023-08-03 | 7.8 High |
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges. |