Vulnerabilities (CVE)

Filtered by vendor Solarwinds Subscribe
Filtered by product Orion Network Performance Monitor
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-8917 1 Solarwinds 1 Orion Network Performance Monitor 2020-08-24 10.0 HIGH 9.8 CRITICAL
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.