The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
References
Configurations
History
21 Nov 2024, 07:46
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
References | () https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-3-1_release_notes.htm - Vendor Advisory | |
References | () https://www.solarwinds.com/trust-center/security-advisories/CVE-2023-23840 - Vendor Advisory |
15 Sep 2023, 13:25
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-3-1_release_notes.htm - Vendor Advisory | |
References | (MISC) https://www.solarwinds.com/trust-center/security-advisories/CVE-2023-23840 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
First Time |
Solarwinds orion Platform
Solarwinds |
|
CWE | CWE-697 | |
CPE | cpe:2.3:a:solarwinds:orion_platform:*:*:*:*:*:*:*:* |
14 Sep 2023, 13:01
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-13 23:15
Updated : 2024-11-21 07:46
NVD link : CVE-2023-23840
Mitre link : CVE-2023-23840
CVE.ORG link : CVE-2023-23840
JSON object : View
Products Affected
solarwinds
- orion_platform
CWE
CWE-697
Incorrect Comparison