peter bassill · operator
$ cve CVE-2024-23472 JSON

CVE-2024-23472

9.6
CRITICAL · CVSS 3.1 · EPSS 18.6% (pctl 97)

Patch early

EPSS 18.6% — above the 10% action threshold.

Description

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.

Scoring

CVSS9.6 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS18.6% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploitnone known
Published2024-07-17
Last modified2026-06-17

Affected (1)

VendorProduct
solarwindsaccess rights manager

References

→ the Explorer  ·  watch your stack  ·  NVD