Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » SolarWinds Fixes 8 Critical Flaws in Access Rights Manager Software
Global Security

SolarWinds Fixes 8 Critical Flaws in Access Rights Manager Software

AdminBy AdminJuly 19, 2024No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 19, 2024Information hallVulnerability / Enterprise Security

SolarWinds has addressed a set of critical security flaws affecting its Access Rights Manager (ARM) software that could be exploited to access sensitive information or execute arbitrary code.

Of the 13 vulnerabilities, eight received a critical severity rating and a CVSS score of 9.6 out of 10.0. The remaining five vulnerabilities were rated as High severity, with four receiving a CVSS score of 7.6 and one receiving a CVSS score of 8.3.

The most serious disadvantages are listed below –

  • CVE-2024-23472 – SolarWinds ARM Directory Traversal Arbitrary file deletion and information disclosure vulnerability
  • CVE-2024-28074 – SolarWinds ARM internal deserialization remote code execution vulnerability
  • CVE-2024-23469 – Solarwinds ARM discovered a dangerous remote code execution vulnerability
  • CVE-2024-23475 – Solarwinds ARM Traversal and Information Disclosure Vulnerability
  • CVE-2024-23467 – Solarwinds ARM Traversal remote code execution vulnerability
  • CVE-2024-23466 – Solarwinds ARM Directory Traversal Remote Code Execution Vulnerability
  • CVE-2024-23470 – Solarwinds ARM UserScriptHumster discovered an unsafe remote command execution vulnerability
  • CVE-2024-23471 – Solarwinds ARM CreateFile Directory Traversal Remote code execution vulnerability

Successful exploitation of the above vulnerabilities could allow an attacker to read and delete files and execute code with elevated privileges.

The vulnerabilities were addressed in version 2024.3, released on July 17, 2024, following responsible disclosure as part of the Trend Micro Zero Day Initiative (ZDI).

Cyber ​​security

The development came after the US Cybersecurity and Infrastructure Security Agency (CISA) placed flaw in passing high-severity paths in SolarWinds Serv-U Path (CVE-2024-28995, CVSS score: 8.6) to the catalog of known vulnerabilities (KEV) after reports of active exploitation in the wild.

A network security company has fallen victim to a a major attack on supply chains in 2020 after the update mechanism associated with the Orion Network Management Platform was compromised Russian hackers apt29 distribute malicious code to downstream customers as part of a high-profile cyber espionage campaign.

The breach prompted the US Securities and Exchange Commission (SEC). file lawsuit against SolarWinds and its chief information security officer (CISO) last October, alleging that the company failed to disclose enough material information to investors regarding cybersecurity risks.

However, a significant part of the claims related to the lawsuit was thrown away by the U.S. District Court for the Southern District of New York on July 18, stating that “these allegations do not allege actionable deficiencies in the company’s reporting of the cybersecurity breach” and that they “impermissibly rely on hindsight and conjecture.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.