Synopsis
The remote host is missing one or more security updates.
Description
The version of SolarWinds ARM installed on the remote host is prior to 2023.2.3. It is, therefore, affected by multiple vulnerabilities as referenced in the arm_2023-2-3 advisory.
- The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability.
If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution. (CVE-2023-40057)
- The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote Code Execution. (CVE-2024-23476)
- The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution. (CVE-2024-23477)
- SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution. (CVE-2024-23478)
- SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution. (CVE-2024-23479)
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Upgrade SolarWinds ARM based upon the guidance specified in arm_2023-2-3.
Plugin Details
File Name: solarwinds_arm_2023-2-3.nasl
Agent: windows
Supported Sensors: Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/a:solarwinds:access_rights_manager
Required KB Items: installed_sw/SolarWinds ARM, SMB/Registry/Enumerated
Exploit Ease: No known exploits are available
Patch Publication Date: 2/15/2024
Vulnerability Publication Date: 2/15/2024