← Vulnerability feed

Vulnerability record · CVE-2024-0692 · published 1 March 2024

CVE-2024-0692: SolarWinds Security Event Manager unauthenticated deserialization RCE

Solarwinds · Security Event Manager

SolarWinds Security Event Manager is vulnerable to remote code execution caused by deserialization of untrusted data (CWE-502). An unauthenticated attacker can abuse the service to run code, which matters because the product is a security monitoring platform and compromise undermines the visibility it is meant to provide.

8.8 CVSS 3.1 High EPSS 92% · top 0.2% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote code execution with high CVSS impact and a very high EPSS score, though exploitation is limited to adjacent network access and no KEV listing or public exploit is confirmed.

What it is

SolarWinds Security Event Manager is vulnerable to remote code execution caused by deserialization of untrusted data (CWE-502). An unauthenticated attacker can abuse the service to run code, which matters because the product is a security monitoring platform and compromise undermines the visibility it is meant to provide.

Impact

An attacker gains remote code execution on the Security Event Manager host, with high impact to confidentiality, integrity and availability per the CVSS vector. This can lead to full control of the appliance and potential tampering with or loss of security event data.

Attack surface

The CVSS vector is AV:A (adjacent network), PR:N and UI:N, so the flaw is reachable from an adjacent network segment without authentication and without user interaction. The description does not specify the exact endpoint or protocol involved.

Exploitation

The record does not list this CVE in CISA KEV and documents no ransomware use, but EPSS is very high at 0.92245 (99.8th percentile), indicating strong predicted exploitation activity. No public exploit code is referenced in the supplied references, which are only vendor advisory and release notes.

What to do

  • Upgrade to the fixed SolarWinds Security Event Manager release referenced in the vendor advisory and 2023.4.1 release notes.
  • Restrict network access to the SEM service so only trusted management hosts on adjacent segments can reach it.
  • Segment and firewall the SEM appliance away from general user and untrusted networks.
  • Monitor vendor advisory and release notes for further updates and apply them promptly.
  • If patching is delayed, isolate the appliance and increase monitoring of its host and service logs.

Detection

  • Monitor SEM and host logs for unexpected process creation or child processes spawned by the SEM service.
  • Alert on anomalous network connections to the SEM service from hosts outside the expected management segment.
  • Look for deserialization-related errors or crashes in SEM application logs that may indicate exploitation attempts.
  • Baseline normal SEM service behavior and alert on deviations such as new listening ports or outbound connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-0692 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2022-38114Solarwinds security event manager cross-site scripting vulnerabilityThis vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling o…EPSS 0.55%5.3CVE-2022-38113Solarwinds security event manager information exposure vulnerabilityThis vulnerability discloses build and services versions in the server response header.EPSS 0.70%5.3CVE-2022-38115Solarwinds security event manager interpretation conflict vulnerabilityInsecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUTEPSS 0.70%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed

Source: NIST National Vulnerability Database (record CVE-2024-0692), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.