Vulnerabilities
Vulnerable Software
Solarwinds:  Security Vulnerabilities
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
CVSS Score
4.8
EPSS Score
0.054
Published
2019-03-21
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
CVSS Score
7.2
EPSS Score
0.081
Published
2019-03-21
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
CVSS Score
9.8
EPSS Score
0.028
Published
2019-03-01
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.
CVSS Score
9.8
EPSS Score
0.364
Published
2019-02-18
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.
CVSS Score
9.8
EPSS Score
0.015
Published
2018-12-05
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
CVSS Score
9.1
EPSS Score
0.014
Published
2018-12-05
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
CVSS Score
7.8
EPSS Score
0.017
Published
2018-09-07
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.
CVSS Score
7.3
EPSS Score
0.011
Published
2018-05-16
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.
CVSS Score
6.5
EPSS Score
0.017
Published
2018-05-16
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
CVSS Score
9.8
EPSS Score
0.594
Published
2017-12-20


Contact Us

Shodan ® - All rights reserved