SolarWinds Flaw Flagged by NATO Pen Tester
ID: 09b3b101-36c9-535d-9f1c-d090c14fe235
STIX ID: report--09b3b101-36c9-535d-9f1c-d090c14fe235
Feed Name: Dark Reading
Threat Score
SolarWinds released version 2024.2 which includes patches for three security flaws—an SWQL injection (CVE-2024-28996, CVSS 7.5), a cross-site scripting issue (CVE-2024-29004, CVSS 7.1), and a race condition in the web console (CVE-2024-28999, CVSS 7.1)—alongside feature and stability improvements; the vendor reports no evidence these vulnerabilities have been exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
