Vulnerability record · CVE-2022-38108 · published 20 October 2022
CVE-2022-38108: SolarWinds Platform deserialization of untrusted data allows command execution
Solarwinds · Orion Platform
SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data (CWE-502), which lets an attacker run arbitrary commands on the host. The flaw matters because the affected component sits in the management plane, where compromise gives broad control over monitored infrastructure. The record does not list specific affected versions or fixed builds beyond the vendor advisory reference.
Description
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command execution in a management platform with a very high EPSS score, tempered by the requirement for admin-level access.
What it is
SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data (CWE-502), which lets an attacker run arbitrary commands on the host. The flaw matters because the affected component sits in the management plane, where compromise gives broad control over monitored infrastructure. The record does not list specific affected versions or fixed builds beyond the vendor advisory reference.
Impact
An attacker with Orion admin-level access to the SolarWinds Web Console can execute arbitrary commands on the server, leading to full control of the SolarWinds instance and any credentials or managed systems it holds.
Attack surface
Reachable remotely over the network through the SolarWinds Web Console (AV:N), but it requires a high-privileged Orion admin account (PR:H) and no user interaction (UI:N). The description does not specify the exact endpoint or payload path.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.689, 99.3rd percentile), indicating elevated likelihood of exploitation. References include a Packet Storm remote command execution write-up and a ZDI advisory, suggesting public technical detail exists.
What to do
- Apply the fix from the SolarWinds trust center advisory for CVE-2022-38108; patch first.
- Restrict and audit Orion admin-level accounts, enforcing least privilege and removing unused admin access.
- Limit network exposure of the SolarWinds Web Console to trusted management networks and place it behind strict access controls.
- Monitor and alert on administrative account creation, privilege changes, and unexpected command execution on SolarWinds hosts.
- Rotate credentials and secrets stored or managed by the SolarWinds instance if compromise is suspected.
Detection
- Hunt for suspicious child processes spawned by SolarWinds/IIS worker processes on Orion servers.
- Review Web Console and Orion admin account activity for logins or actions from unusual sources or at unusual times.
- Monitor for deserialization-related errors or anomalous requests to SolarWinds web endpoints.
- Correlate host telemetry on SolarWinds servers with outbound connections or command execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-38108 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-38108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.