|
|||
Rule General Information |
---|
Release Date: | 2019-03-20 | |
Rule Name: | SolarWinds Orion NPM OrionModuleEngine Remote Code Execution Vulnerability (CVE-2019-8917) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user. | |
Impact: | An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others | |
Reference: | SecurityFocusBID:107061 https://github.com/VerSprite/research/blob/master/advisories/VS-2019-001.md |
|
Solutions |
---|
Upgrading to version 12.4 eliminates this vulnerability. |