SolarWinds Platform 2024.4.0 < 2025.1 Multiple Vulnerabilities

low Nessus Plugin ID 216060

Synopsis

SolarWinds Platform is affected by a vulnerability

Description

The version of SolarWinds Platform installed on the remote host is prior to 2025.1. It is, therefore, affected by multiple vulnerabilities as referenced in the solarwinds_platform_2025_1 advisory.

- The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message.
While the data does not provide anything sensitive, the information could assist an attacker in other malicious actions. (CVE-2024-52611)

- SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of a malicious web request. (CVE-2024-52606)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to SolarWinds Platform version 2025.1 or later.

See Also

http://www.nessus.org/u?1e6c794a

http://www.nessus.org/u?87b31046

Plugin Details

Severity: Low

ID: 216060

File Name: solarwinds_solarwinds_platform_2025_1.nasl

Version: 1.1

Type: combined

Agent: windows

Family: CGI abuses

Published: 2/11/2025

Updated: 2/11/2025

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: Low

Base Score: 2.7

Temporal Score: 2

Vector: CVSS2#AV:A/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2024-52611

CVSS v3

Risk Factor: Low

Base Score: 3.5

Temporal Score: 3.1

Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:solarwinds:orion_platform

Required KB Items: installed_sw/SolarWinds Orion Core

Exploit Ease: No known exploits are available

Patch Publication Date: 2/11/2025

Vulnerability Publication Date: 2/11/2025

Reference Information

CVE: CVE-2024-52606, CVE-2024-52611