SolarWinds Reveals RCE Flaw in Access Rights Manager
SolarWinds Reveals RCE Flaw in Access Rights Manager
13 September 2024
SolarWinds has disclosed two vulnerabilities in their Access Rights Manager (ARM) software: CVE-2024-28990 (CVSS 6. 3) allows for a hardcoded credential authentication bypass, while CVE-2024-28991 (CVSS 9. 0) enables remote code execution.