InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: SolarWinds releases patch for critical ARM vulnerability that could enable RCE attacks
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > SolarWinds releases patch for critical ARM vulnerability that could enable RCE attacks
Technology

SolarWinds releases patch for critical ARM vulnerability that could enable RCE attacks

September 17, 2024 2 Min Read
Share
SolarWinds
SHARE

SolarWinds has released fixes to address two security flaws in its Access Rights Manager (ARM) software, including a critical vulnerability that could lead to remote code execution.

This vulnerability is CVE-2024-28991It has been rated 9.0 out of a maximum of 10.0 on the CVSS scoring system. It is described as an instance of untrusted data deserialization.

“A remote code execution vulnerability has been identified in SolarWinds Access Rights Manager (ARM),” the company said in its advisory. “Successful exploitation of this vulnerability could allow an authenticated user to exploit the service, leading to remote code execution.”

Piotr Basidlo, a security researcher at the Trend Micro Zero Day Initiative (ZDI), is said to have discovered and reported the flaw on May 24, 2024.

ZDI, which assigned the flaw a CVSS score of 9.9, said the flaw exists in a class called JsonSerializationBinder and stems from a lack of proper validation of user-supplied data, exposing ARM devices to a deserialization vulnerability that could be exploited to execute arbitrary code.

“Although authentication is required to exploit this vulnerability, existing authentication mechanisms can be circumvented,” ZDI said.

Another vulnerability addressed by SolarWinds is a medium severity vulnerability in ARM (CVE-2024-28990, CVSS score: 6.3) that exposes hardcoded credentials that, if exploited, could lead to unauthorized access to the RabbitMQ management console.

Both issues have been fixed in ARM version 2024.3.1. While there is currently no evidence that the vulnerabilities are being actively exploited in the wild, we encourage you to update to the latest version as soon as possible to protect yourself from potential threats.

See also  Exposed Selenium Grid servers targeted for cryptomining and proxyjacking

This development comes after D-Link resolved three critical vulnerabilities (CVE-2024-45694, CVE-2024-45695, and CVE-2024-45697, CVSS score: 9.8) affecting its DIR-X4860, DIR-X5460, and COVR-X1870 routers.The vulnerabilities could allow remote execution of arbitrary code and system commands.

Share This Article
Twitter Copy Link
Previous Article Meme Code September 2024 Meme Code September 2024
Next Article Secret group recruits far-right candidates for key U.S. House races, which could benefit Democrats Secret group recruits far-right candidates for key U.S. House races, which could benefit Democrats
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

Designing Identity-Focused Incident Response Playbooks
Technology

Designing Identity-Focused Incident Response Playbooks

2 Min Read
Progress WhatsUp Gold
Technology

Progress WhatsUp Gold Critical Flaw Exploited Just Hours After PoC Release

3 Min Read
mm
Technology

AlphaProteo: Google DeepMind’s Breakthrough in Protein Design

14 Min Read
Google Workspace
Technology

How to investigate ChatGPT activity in Google Workspace

5 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?