本ページは solarwinds network_configuration_manager に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2023-40055 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227 | [email protected] | 8.0 | 2.14% | 2023-11-09 | 2026-06-17 |
| CVE-2023-40054 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226 | [email protected] | 8.0 | 2.98% | 2023-11-09 | 2026-06-17 |
| CVE-2023-33228 | The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information. | [email protected] | 4.5 | 0.44% | 2023-11-01 | 2026-06-17 |
| CVE-2023-33227 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges. | [email protected] | 8.0 | 1.84% | 2023-11-01 | 2026-06-17 |
| CVE-2023-33226 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. | [email protected] | 8.0 | 1.84% | 2023-11-01 | 2026-06-17 |
| CVE-2021-35226 | An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role. | [email protected] | 6.5 | 0.45% | 2022-10-10 | 2026-06-16 |
| CVE-2014-3459 | Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEstrarg1 property. | [email protected] | 6.8 | 11.56% | 2014-08-07 | 2026-06-16 |