
Cloud Vulnerability DB
A community-led vulnerabilities database
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability, tracked as CVE-2024-28991. The vulnerability was discovered and reported by Piotr Bazydlo of Trend Micro Zero Day Initiative. The issue affects SolarWinds ARM 2024.3 and prior versions, and was publicly disclosed on September 12, 2024 (Vendor Advisory).
The vulnerability exists within the JsonSerializationBinder class and stems from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. The flaw has been classified as CWE-502 (Deserialization of Untrusted Data). The vulnerability has received a CVSS v3.1 base score of 9.0 CRITICAL with the vector string CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (ZDI Advisory).
If successfully exploited, this vulnerability would allow an authenticated attacker to execute arbitrary code in the context of SYSTEM. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed (ZDI Advisory).
The vulnerability requires an authenticated user access, though the authentication mechanism can potentially be bypassed. The attack complexity is considered low, requiring no user interaction to exploit. The vulnerability was reported to the vendor on May 24, 2024, and was publicly disclosed on September 13, 2024 (ZDI Advisory).
SolarWinds has addressed this vulnerability by releasing Access Rights Manager (ARM) version 2024.3.1. Users are strongly advised to upgrade to this latest version to protect against potential exploitation (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."