peter bassill · operator
$ cve CVE-2024-28075 JSON

CVE-2024-28075

9.0
CRITICAL · CVSS 3.1 · EPSS 78% (pctl 100)

Patch early

EPSS 78% — above the 10% action threshold.

Description

The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS78.03% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2024-05-14
Last modified2026-06-17

Affected (1)

VendorProduct
solarwindsaccess rights manager

References

→ the Explorer  ·  watch your stack  ·  NVD