CVE-2024-52606
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 11, 2025
Updated: Feb 25, 2025
CWE ID 918
Summary
CVE-2024-52606 is a serious vulnerability affecting the SolarWinds Platform. Malicious actors can exploit this server-side request forgery (SSRF) weakness, bypassing proper input sanitation. An unauthorized web request can manipulate the server's response, potentially leading to unauthorized access or data theft. This issue highlights the importance of regular software updates and robust input validation mechanisms. Users are strongly advised to patch their SolarWinds installations as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- SolarWinds Platform
Affected Vendors
- SolarWinds