Solarwinds
Solarwinds Access Rights Manager: vulnerabilidades y CVE
Solarwinds Access Rights Manager tiene 33 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses1
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-28326 | Alta (8.8) | 0.69% | — | 17 sept 2026 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key. |
| CVE-2024-28991 | Alta (8) | 3.1% | — | 12 sept 2024 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote… |
| CVE-2024-28990 | Alta (8.8) | 0.47% | — | 12 sept 2024 | SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank… |
| CVE-2024-28993 | Alta (8.3) | 0.95% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak… |
| CVE-2024-28992 | Alta (8.3) | 1.9% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak… |
| CVE-2024-28074 | Alta (8.8) | 11% | — | 17 jul 2024 | It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to… |
| CVE-2024-23475 | Alta (8.8) | 2.1% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak… |
| CVE-2024-23474 | Alta (8.8) | 1.5% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability. |
| CVE-2024-23472 | Alta (8) | 19% | — | 17 jul 2024 | SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM. |
| CVE-2024-23471 | Alta (8.8) | 1.3% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote… |
| CVE-2024-23470 | Alta (8.8) | 1.2% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and… |
| CVE-2024-23469 | Alta (8.8) | 18% | — | 17 jul 2024 | SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges. |
| CVE-2024-23468 | Alta (8.3) | 3.4% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak… |
| CVE-2024-23467 | Alta (8.8) | 2.9% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code execution. |
| CVE-2024-23466 | Alta (8.8) | 2.5% | — | 17 jul 2024 | SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM… |
| CVE-2024-23465 | Alta (8.8) | 1.9% | — | 17 jul 2024 | The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin access within the Active Directory… |
| CVE-2024-28075 | Alta (8) | 78% | — | 14 may 2024 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend… |
| CVE-2024-23473 | Crítica (9.8) | 1.1% | — | 14 may 2024 | The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend… |
| CVE-2024-23479 | Crítica (9.6) | 5.8% | — | 15 feb 2024 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code… |
| CVE-2024-23478 | Alta (8) | 82% | — | 15 feb 2024 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in… |
| CVE-2024-23477 | Crítica (9.6) | 7.8% | — | 15 feb 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote… |
| CVE-2024-23476 | Crítica (9.6) | 7.1% | — | 15 feb 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote… |
| CVE-2023-40057 | Crítica (9) | 4.9% | — | 15 feb 2024 | The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote… |
| CVE-2023-40058 | Media (6.5) | 0.80% | — | 21 dic 2023 | Sensitive data was added to our public-facing knowledgebase that, if exploited, could be used to access components of Access Rights Manager (ARM) if the threat actor is in the same environment. |
| CVE-2023-35187 | Crítica (9.8) | 3.0% | — | 19 oct 2023 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated user to achieve the Remote Code Execution. |
| CVE-2023-35186 | Alta (8.8) | 2.2% | — | 19 oct 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. |
| CVE-2023-35185 | Media (6.8) | 1.1% | — | 19 oct 2023 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges. |
| CVE-2023-35184 | Crítica (9.8) | 1.4% | — | 19 oct 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution. |
| CVE-2023-35183 | Alta (7.8) | 0.20% | — | 19 oct 2023 | The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation. |
| CVE-2023-35182 | Crítica (9.8) | 2.4% | — | 19 oct 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.