Security Advisory

CVE-2019-8917

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-02-18 19:00:00
Last updated 2024-08-04 21:31:37
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.