216.73.217.22

CVE-2024-28991

· Published 12/09/2024 16:16 · Modified 21/12/2025 07:45 · Author: The MITRE Corporation

Labels: CVE-2024-28991 2024-09-12CVE-2024-28991CWE-502NVD-CWE-noinfo[email protected]

Essential information

Published
12/09/2024 16:16
Modified
21/12/2025 07:45
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.0 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:A/C:H/I:H/A:H

CVSS metrics

Description

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
solarwinds / access rights manager cpe:2.3:a:solarwinds:access_rights_manager:*:*:*:*:*:*:*:*

References