Beveiligingsadvies

CVE-2019-8917

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-02-18 19:00:00
Laatst bijgewerkt 2024-08-04 21:31:37
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.