QID 379386

Date Published: 2024-02-16

QID 379386: SolarWinds Access Rights Manager (ARM) Multiple Vulnerabilities

SolarWinds ARM is a tool that enables organizations to manage and audit user access rights across the IT environments

Affected versions:
SolarWinds ARM prior to version 2023.2.3

QID Detection Logic(Authenticated):
This QID checks for the SolarWinds.ARM.Core.dll's file version fetched from the registry keys "HKEY_LOCAL_MACHINE\SOFTWARE\SolarWinds\ARM" and "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\SolarWinds\ARM" .

Vulnerable versions of SolarWinds ARM may allow an attacker to perform Remote Code Execution (RCE).

  • CVSS V3 rated as Critical - 9.6 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution
    For more information about patch and fixes visit SolarWinds ARM 2023.2.3.
    Software Advisories
    Advisory ID Software Component Link
    SolarWinds ARM 2023.2.3 URL Logo documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm