CVE-2024-52606

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 25, 2025
CWE ID 918

Summary

CVE-2024-52606 is a serious vulnerability affecting the SolarWinds Platform. Malicious actors can exploit this server-side request forgery (SSRF) weakness, bypassing proper input sanitation. An unauthorized web request can manipulate the server's response, potentially leading to unauthorized access or data theft. This issue highlights the importance of regular software updates and robust input validation mechanisms. Users are strongly advised to patch their SolarWinds installations as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SolarWinds Platform

Affected Vendors

  • SolarWinds