Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-23836: SolarWinds Trust Center Security Advisories | CVE-2023-23836

SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.

CVE
#sql#vulnerability#web#windows#microsoft#cisco#auth#zero_day
  • Government

  • Customer Portal

  • Partners

    • Portal Login
    • Program Overview
    • Become a Partner
  • Events

  • Contact Us

  • English

    • Deutsch
    • Español
    • Français
    • 日本語
    • 한국어
    • Português
    • 中文
  • PRODUCTS

    • OBSERVABILITY

    • Network Management

    • Systems Management

    • Database Management

    • IT Service Management

    • Application Management

    • IT Security

    • ALL PRODUCTS & FREE TRIALS

  • Solutions

    • BY NEED

    • BY INDUSTRY

    • BY TECHNOLOGY

  • Support

  • Community

    THWACK

    Connect with more than 180,000+ community members. Get help, be heard by us and do your job better using our products.

    • View THWACK
  • FREE TRIALS

  • Contact Sales

  • Online Quote

  • PRODUCTS

    • OBSERVABILITY
      • SolarWinds Observability
      • Hybrid Cloud Observability
    • Network Management
      • Network Performance Monitor
      • NetFlow Traffic Analyzer
      • Network Configuration Manager
      • IP Address Manager
      • User Device Tracker
      • VoIP & Network Quality Manager
      • Network Automation Manager
      • Log Analyzer
      • Network Topology Mapper
      • Engineer’s Toolset
      • ipMonitor
      • Kiwi CatTools
      • Kiwi Syslog Server
      • Network Bandwidth Analyzer Pack
      • Log and Network Performance Pack
      • IP Control Bundle
    • Systems Management
      • Server & Application Monitor
      • Virtualization Manager
      • Storage Resource Monitor
      • ipMonitor
      • Serv-U Managed File Transfer
      • Serv-U Secured FTP
      • Server Configuration Monitor
      • Log Analyzer
      • Access Rights Manager
      • AppOptics
      • Web Performance Monitor
      • Systems Management Bundle
      • Server Performance & Configuration Bundle
      • Log and Systems Performance Pack
      • Application Performance Optimization Pack
      • IT Operations Manager
      • Web Application Monitoring & Performance Pack
    • Database Management
      • Database Performance Analyzer
      • SQL Sentry
      • Database Performance Monitor
      • Database Mapper
      • Task Factory
      • Database Insights for SQL Server
    • IT Service Management
      • Service Desk
      • Web Help Desk
      • Dameware Remote Everywhere
      • Dameware Remote Support
      • Dameware Mini Remote Control
    • Application Management
      • SolarWinds Observability
      • AppOptics
      • Server & Application Monitor
      • Loggly
      • Log Analyzer
      • Papertrail
      • Pingdom
    • IT Security
      • Access Rights Manager
      • Security Event Manager
      • Server Configuration Monitor
      • Patch Manager
      • Identity Monitor
      • Serv-U Managed File Transfer
      • Serv-U Secured FTP
      • Serv-U Gateway
  • Solutions

    • BY NEED
      • Hybrid Cloud Observability
      • SolarWinds Observability
      • Database Management
      • Application Performance Management
      • SolarWinds Orion Platform
      • Network Management
      • IT Asset Management
      • IT Security
      • IT Operations Management
      • IT Help Desk
      • Remote Monitoring
      • Infrastructure
      • IT Service Management
      • IT Automation
      • Compliance
      • Remote Infrastructure Management
      • Hybrid Systems Monitoring
      • Secure Remote Access
    • BY INDUSTRY
      • Small Business
      • Enterprise
      • Education
      • Public Sector
    • BY TECHNOLOGY
      • Azure
      • Active Directory
      • Cisco
      • Office 365
      • MySQL
      • SQL Diagnostic
  • Support

    • Renew Maintenance
      • Renew Maintenance
      • Learn about Auto-Renewal
    • Access the Success Center
      • Access the Success Center
      • Onboarding/Deployment Services
      • Premium Support Offerings
    • Technical Support
      • Americas: +1-512-682-9300
      • EMEA: +353 21 5002900
      • APAC: +65 6593 7600
      • Submit a Ticket
      • Supported Versions
      • End of Life Policy
      • End of Life Policy for SaaS Products
    • Training & Certification
      • SolarWinds Academy
      • SolarWinds Certified Professional
    • Customer Portal
      • Access the Customer Portal
  • Community

    • THWACK
      • View THWACK
    • Orange Matter
      • View Orange Matter
    • LogicalRead Blog
      • View LogicalRead Blog
    • Secure by Design Resource Center
      • View Resources
  • FREE TRIALS

  • Contact Sales

  • Online Quote

  • View All Products View Free Tools

SolarWinds Platform Deserialization of Untrusted Data Vulnerability (CVE-2023-23836)

Summary

SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.

Affected Products

  • SolarWinds Platform 2022.4.1

Fixed Software Release

  • SolarWinds Platform 2023.1

Acknowledgments

  • Piotr Bazydlo (@chudypb) of Trend Micro Zero Day Initiative

Advisory Details

First Published

02/15/2023

Fixed Version

SolarWinds Platform 2023.1

Workarounds

SolarWinds recommends customers upgrade to SolarWinds Platform version 2023.1 as soon as it becomes available. The expected release is by the end of February 2023. SolarWinds also recommends customers to follow the guidance provided in the SolarWinds Secure Configuration Guide, and ensure only authorized users can access the SolarWinds Platform. Special attention should be given to the following points from the documentation:

  • Be careful not to expose your SolarWinds Platform website on the public internet. If you must enable outbound internet access from SolarWinds servers, create a strict allow list and block all other traffic. See SolarWinds Platform Product Features Affected by Internet Access.
  • Disable unnecessary ports, protocols, and services on your host operating system and on applications like SQL Server. For more details, see the SolarWinds Port Requirements guide and Best practices for configuring Windows Defender Firewall (© 2023 Microsoft, available at https://docs.microsoft.com, obtained on January 10, 2023.)
  • Apply proper segmentation controls on the network where you have deployed the SolarWinds Platform and SQL Server instances.
  • Configure the firewall for the main polling engine to limit and restrict all inbound and outbound access for port 5671. Port 5671 should only communicate to your other SolarWinds Servers (in case of High Availability, both Active and Standby Primary Polling Engine Servers). You can check these by querying the Orion Servers table in the SolarWinds Platform database. Ensure this rule is updated when the configuration of SolarWinds Platform changes, for example, when you add new servers.

We’re Geekbuilt.®

Developed by network and systems engineers who know what it takes to manage today’s dynamic IT environments, SolarWinds has a deep connection to the IT community.

The result? IT management products that are effective, accessible, and easy to use.

© 2023 SolarWinds Worldwide, LLC. All rights reserved.

Related news

CVE-2022-47507: SolarWinds Platform 2023.1 Release Notes

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907