CVE-2024-23465

The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin access within the Active Directory environment.  
Configurations

Configuration 1 (hide)

cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:*

History

10 Sep 2024, 18:56

Type Values Removed Values Added
First Time Solarwinds access Rights Manager
Solarwinds
References () https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm - () https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2024-3_release_notes.htm - Vendor Advisory
CVSS v2 : unknown
v3 : 8.3
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:*

18 Jul 2024, 12:28

Type Values Removed Values Added
Summary
  • (es) Se descubrió que SolarWinds Access Rights Manager era susceptible a una vulnerabilidad de omisión de autenticación. Esta vulnerabilidad permite que un usuario no autenticado obtenga acceso de administrador de dominio dentro del entorno de Active Directory.

17 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-17 15:15

Updated : 2024-09-10 18:56


NVD link : CVE-2024-23465

Mitre link : CVE-2024-23465

CVE.ORG link : CVE-2024-23465


JSON object : View

Products Affected

solarwinds

  • access_rights_manager
CWE
CWE-287

Improper Authentication