CVE-2023-23836 is a deserialization of untrusted data vulnerability affecting SolarWinds Platform version 2022.4.1. This high-severity vulnerability (CVSS 7.2) allows a remote attacker with existing Orion admin-level credentials to the SolarWinds Web Console to execute arbitrary commands, leading to complete compromise of confidentiality, integrity, and availability. While there is no public exploit code or evidence of active exploitation, its high EPSS score and mention in security media indicate significant potential risk and community awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2022.4.1CPE matchmatch criteria | cpe:2.3:a:solarwinds:orion_platform:2022.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.