SolarWinds Releases Security Update for Security Event Manager
Update addresses a vulnerability that could lead to RCE and 4 third-party vulnerabilities in SEM
Summary
Update addresses a vulnerability that could lead to RCE and 4 third-party vulnerabilities in SEM
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
SolarWinds has released a security update to address a deserialisation of untrusted data vulnerability in Security Event Manager (SEM), which is the SolarWinds version of a SIEM tool. An unauthenticated attacker could exploit this vulnerability by abusing SolarWinds' service, leading to remote code execution (RCE). This vulnerability is rated as high with a CVSSv3 score of 8.8.
The update also addresses 4 third-party vulnerabilities:
- CVE-2023-48795 Terrapin-Attack Vulnerability CVSSv3 score - 5.9 Medium
- CVE-2023-3961 Path Traversal Vulnerability CVSSv3 score - 9.8 Critical
- CVE-2023-4154 Broken Access Control Vulnerability CVSSv3 score - 6.5 Medium
- CVE-2023-42670 Denial of Service Vulnerability CVSSv3 score - 6.5 Medium
Remediation advice
Affected organisations are encouraged to review the SolarWinds security advisory for CVE-2024-0692, the SEM 2023.4.1 release notes, and apply any necessary updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 4 March 2024 4:46 pm