Cyber999 Advisories

3 October 2024     Advisory

MA-1163.102024: MyCERT Advisory - RCE Vulnerability in SolarWinds ARM


1.0 Introduction
Recently, SolarWinds has identified critical security vulnerabilities, CVE-2024-28990 and CVE-2024-28991 which are affecting certain versions of their software products.

2.0 Impact
These vulnerabilities could allow an attacker to gain unauthorized access to the SolarWinds platform, potentially compromising sensitive data and system integrity. Exploitation of this vulnerability may result in unauthorized modification or deletion of data, exposure of confidential information, or denial of service (DoS) attacks.

3.0 Affected system/product/version

  • SolarWinds ARM 2024.3 and prior versions

4.0 Related CVE Details

Title Severity CVE
SolarWinds Access Rights Manager (ARM) Hardcoded Credentials Authentication Bypass Vulnerability 6.3 Medium CVE-2024-28990
SolarWinds Access Rights Manager (ARM) Deserialization of Untrusted Data Remote Code Execution 9.0 High CVE-2024-28991

5.0 Recommendations
CyberSecurity Malaysia advises all users and administrators to immediately review SolarWinds’ official advisories and update their systems as per the following recommendation.

Update Access Rights Manager to version 2024.3.1 to apply security enhancements and performance updates. 

Kindly refer to the following URL:

Generally, we advise users to be updated with the latest security announcements by the vendor and follow best practice security policies to determine which updates should be applied.

For further enquiries, please contact Cyber999 Incident Response Centre through the following channels:

E-mail: cyber999[at]cybersecurity.my 
Phone: 1-300-88-2999 (monitored during business hours) 
Mobile: +60 19 2665850 (24x7 call incident reporting) 
Business Hours: Mon - Fri 08:30 -17:3the 0 MYT 
Web:  https://www.mycert.org.my

6.0 References

logo
CyberSecurity Malaysia is the national cyber security specialist agency under the purview of the Ministry of Digital (KD)
 
Contact Us

  • CyberSecurity Malaysia,
    Level 7 Tower 1, Menara Cyber Axis, Jalan Impact,
    63000 Cyberjaya, Selangor Darul Ehsan, Malaysia.

  • enquiry@cybersecurity.my

  • +603 - 8800 7999

  • +603 - 8008 7000

TOP
ASK Byte
Chatbot Portal

Hi, I am ASK Byte. Please submit your questions about the portal and I will try to get answers from online knowledge stores.

Hi, Saya Admin Chatbot. Saya sedia chat dengan anda secara terus. Bagaimana saya boleh membantu anda?

Click the button below to interact with the CSM chatbot

Proceed