CVE-2019-8917
18.02.2019, 19:29
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.Enginsight
| Vendor | Product | Version |
|---|---|---|
| solarwinds | orion_network_performance_monitor | 𝑥 < 12.4 |
𝑥
= Vulnerable software versions