InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: SolarWinds releases patch for critical ARM vulnerability that could enable RCE attacks
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > SolarWinds releases patch for critical ARM vulnerability that could enable RCE attacks
Technology

SolarWinds releases patch for critical ARM vulnerability that could enable RCE attacks

September 17, 2024 2 Min Read
Share
SolarWinds
SHARE

SolarWinds has released fixes to address two security flaws in its Access Rights Manager (ARM) software, including a critical vulnerability that could lead to remote code execution.

This vulnerability is CVE-2024-28991It has been rated 9.0 out of a maximum of 10.0 on the CVSS scoring system. It is described as an instance of untrusted data deserialization.

“A remote code execution vulnerability has been identified in SolarWinds Access Rights Manager (ARM),” the company said in its advisory. “Successful exploitation of this vulnerability could allow an authenticated user to exploit the service, leading to remote code execution.”

Piotr Basidlo, a security researcher at the Trend Micro Zero Day Initiative (ZDI), is said to have discovered and reported the flaw on May 24, 2024.

ZDI, which assigned the flaw a CVSS score of 9.9, said the flaw exists in a class called JsonSerializationBinder and stems from a lack of proper validation of user-supplied data, exposing ARM devices to a deserialization vulnerability that could be exploited to execute arbitrary code.

“Although authentication is required to exploit this vulnerability, existing authentication mechanisms can be circumvented,” ZDI said.

Another vulnerability addressed by SolarWinds is a medium severity vulnerability in ARM (CVE-2024-28990, CVSS score: 6.3) that exposes hardcoded credentials that, if exploited, could lead to unauthorized access to the RabbitMQ management console.

Both issues have been fixed in ARM version 2024.3.1. While there is currently no evidence that the vulnerabilities are being actively exploited in the wild, we encourage you to update to the latest version as soon as possible to protect yourself from potential threats.

See also  Liza Colon-Zayas: 5 things about the Emmy-winning actress from 'The Bear'

This development comes after D-Link resolved three critical vulnerabilities (CVE-2024-45694, CVE-2024-45695, and CVE-2024-45697, CVSS score: 9.8) affecting its DIR-X4860, DIR-X5460, and COVR-X1870 routers.The vulnerabilities could allow remote execution of arbitrary code and system commands.

Share This Article
Twitter Copy Link
Previous Article Meme Code September 2024 Meme Code September 2024
Next Article Secret group recruits far-right candidates for key U.S. House races, which could benefit Democrats Secret group recruits far-right candidates for key U.S. House races, which could benefit Democrats
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

WordPress to Require Two-Factor Authentication for Plugin and Theme Developers
Technology

WordPress to Require Two-Factor Authentication for Plugin and Theme Developers

3 Min Read
mm
Technology

How AI can help map the universe

9 Min Read
HTTP Headers for Credential Theft
Technology

Cybercriminals exploit HTTP headers to steal credentials through mass phishing attacks

7 Min Read
ScRansom Ransomware
Technology

CosmicBeetle partners with RansomHub to deploy custom ScRansom ransomware

8 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?