← Vulnerability feed

Vulnerability record · CVE-2015-5371 · published 6 July 2015

CVE-2015-5371: SolarWinds Storage Manager AuthenticationFilter allows arbitrary script upload and execution

Solarwinds · Storage Manager

The AuthenticationFilter class in SolarWinds Storage Manager fails to properly restrict file uploads, letting a remote attacker upload and execute arbitrary scripts. Because the flaw is reachable without authentication and yields full control of confidentiality, integrity and availability, it is a severe pre-auth remote code execution issue. The record does not specify affected versions or the exact request path.

10.0 CVSS 2.0 High EPSS 93% · top 0.2%
10.0CVSS 2.0 base score
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable arbitrary script upload and execution with a CVSS 2.0 score of 10 and very high EPSS probability warrants critical priority.

What it is

The AuthenticationFilter class in SolarWinds Storage Manager fails to properly restrict file uploads, letting a remote attacker upload and execute arbitrary scripts. Because the flaw is reachable without authentication and yields full control of confidentiality, integrity and availability, it is a severe pre-auth remote code execution issue. The record does not specify affected versions or the exact request path.

Impact

An unauthenticated attacker can upload and run arbitrary scripts on the server, gaining code execution in the context of the affected service and potentially full control of the host.

Attack surface

Reached over the network via the Storage Manager web interface; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The description does not name the specific endpoint or parameter.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high at 0.93162 (99.8th percentile), indicating strong predicted exploitation activity. Reference tags are empty, so no public exploit or PoC is confirmed by this record.

What to do

  • Apply the vendor fix for SolarWinds Storage Manager; if no patch is available for your version, upgrade to a supported release.
  • Restrict network access to the Storage Manager web interface to trusted management networks only.
  • Disable or block script execution in any upload or storage directories used by the application.
  • Run the service with least privilege and isolate it from other systems to limit post-exploitation movement.
  • Monitor vendor advisories and the ZDI reference for updated remediation guidance.

Detection

  • Alert on file upload requests to Storage Manager endpoints that result in executable script files being written to web-accessible directories.
  • Monitor for unexpected script interpreter or web server child processes spawned by the Storage Manager service.
  • Review web server and application logs for anomalous POST requests or unusual file extensions around the upload path.
  • Baseline and alert on new or modified files in Storage Manager upload and web root directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-5371 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2015-5371), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.