Lucene search

K
zdiAnonymousZDI-24-008
HistoryJan 04, 2024 - 12:00 a.m.

SolarWinds Access Rights Manager Hardcoded Credentials Authentication Bypass Vulnerability

2024-01-0400:00:00
Anonymous
www.zerodayinitiative.com
12
solarwinds
access rights manager
hardcoded credentials
authentication bypass
vulnerability
remote attackers
exploit
rabbitmq configuration

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

38.5%

This vulnerability allows remote attackers to bypass authentication on affected installations of SolarWinds Access Rights Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of a RabbitMQ instance. The issue results from the use of hard-coded credentials. An attacker can leverage this vulnerability to bypass RabbitMQ authentication.

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

38.5%

Related for ZDI-24-008