Intrusion Prevention

SolarWinds.Orion.NPM.OrionModuleEngine.Remote.Code.Execution

Description

This indicates an attack attempt to exploit a Remote Code Execution Vulnerability in SolarWinds Orion NPM.
A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted InvokeActionMethod request to the target system. Successful exploitation results in the execution of arbitrary code on the target system with the SYSTEM privileges.

Affected Products

SolarWinds Orion NPM prior to 12.4

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Refer to the vendor supplied advisory for updates:
https://support.solarwinds.com/Success_Center/Knowledgebase_Articles/CVE-2019-8917_NPM_Vulnerability

CVE References

CVE-2019-8917