Vulnerability record · CVE-2015-5371 · published 6 July 2015
CVE-2015-5371: SolarWinds Storage Manager AuthenticationFilter allows arbitrary script upload and execution
Solarwinds · Storage Manager
The AuthenticationFilter class in SolarWinds Storage Manager fails to properly restrict file uploads, letting a remote attacker upload and execute arbitrary scripts. Because the flaw is reachable without authentication and yields full control of confidentiality, integrity and availability, it is a severe pre-auth remote code execution issue. The record does not specify affected versions or the exact request path.
Description
The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary script upload and execution with a CVSS 2.0 score of 10 and very high EPSS probability warrants critical priority.
What it is
The AuthenticationFilter class in SolarWinds Storage Manager fails to properly restrict file uploads, letting a remote attacker upload and execute arbitrary scripts. Because the flaw is reachable without authentication and yields full control of confidentiality, integrity and availability, it is a severe pre-auth remote code execution issue. The record does not specify affected versions or the exact request path.
Impact
An unauthenticated attacker can upload and run arbitrary scripts on the server, gaining code execution in the context of the affected service and potentially full control of the host.
Attack surface
Reached over the network via the Storage Manager web interface; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The description does not name the specific endpoint or parameter.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high at 0.93162 (99.8th percentile), indicating strong predicted exploitation activity. Reference tags are empty, so no public exploit or PoC is confirmed by this record.
What to do
- Apply the vendor fix for SolarWinds Storage Manager; if no patch is available for your version, upgrade to a supported release.
- Restrict network access to the Storage Manager web interface to trusted management networks only.
- Disable or block script execution in any upload or storage directories used by the application.
- Run the service with least privilege and isolate it from other systems to limit post-exploitation movement.
- Monitor vendor advisories and the ZDI reference for updated remediation guidance.
Detection
- Alert on file upload requests to Storage Manager endpoints that result in executable script files being written to web-accessible directories.
- Monitor for unexpected script interpreter or web server child processes spawned by the Storage Manager service.
- Review web server and application logs for anomalous POST requests or unusual file extensions around the upload path.
- Baseline and alert on new or modified files in Storage Manager upload and web root directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5371 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5371), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.