Vulnerability record · CVE-2024-0692 · published 1 March 2024
CVE-2024-0692: SolarWinds Security Event Manager unauthenticated deserialization RCE
Solarwinds · Security Event Manager
SolarWinds Security Event Manager is vulnerable to remote code execution caused by deserialization of untrusted data (CWE-502). An unauthenticated attacker can abuse the service to run code, which matters because the product is a security monitoring platform and compromise undermines the visibility it is meant to provide.
Description
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityUnauthenticated remote code execution with high CVSS impact and a very high EPSS score, though exploitation is limited to adjacent network access and no KEV listing or public exploit is confirmed.
What it is
SolarWinds Security Event Manager is vulnerable to remote code execution caused by deserialization of untrusted data (CWE-502). An unauthenticated attacker can abuse the service to run code, which matters because the product is a security monitoring platform and compromise undermines the visibility it is meant to provide.
Impact
An attacker gains remote code execution on the Security Event Manager host, with high impact to confidentiality, integrity and availability per the CVSS vector. This can lead to full control of the appliance and potential tampering with or loss of security event data.
Attack surface
The CVSS vector is AV:A (adjacent network), PR:N and UI:N, so the flaw is reachable from an adjacent network segment without authentication and without user interaction. The description does not specify the exact endpoint or protocol involved.
Exploitation
The record does not list this CVE in CISA KEV and documents no ransomware use, but EPSS is very high at 0.92245 (99.8th percentile), indicating strong predicted exploitation activity. No public exploit code is referenced in the supplied references, which are only vendor advisory and release notes.
What to do
- Upgrade to the fixed SolarWinds Security Event Manager release referenced in the vendor advisory and 2023.4.1 release notes.
- Restrict network access to the SEM service so only trusted management hosts on adjacent segments can reach it.
- Segment and firewall the SEM appliance away from general user and untrusted networks.
- Monitor vendor advisory and release notes for further updates and apply them promptly.
- If patching is delayed, isolate the appliance and increase monitoring of its host and service logs.
Detection
- Monitor SEM and host logs for unexpected process creation or child processes spawned by the SEM service.
- Alert on anomalous network connections to the SEM service from hosts outside the expected management segment.
- Look for deserialization-related errors or crashes in SEM application logs that may indicate exploitation attempts.
- Baseline normal SEM service behavior and alert on deviations such as new listening ports or outbound connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-0692 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-0692), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.