This page lists publicly disclosed CVE vulnerabilities affecting solarwinds network_configuration_manager (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-40055 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227 | [email protected] | 8.0 | 3.55% | 2023-11-09 | 2024-11-21 |
| CVE-2023-40054 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226 | [email protected] | 8.0 | 1.39% | 2023-11-09 | 2024-11-21 |
| CVE-2023-33228 | The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information. | [email protected] | 4.5 | 0.04% | 2023-11-01 | 2024-11-21 |
| CVE-2023-33227 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges. | [email protected] | 8.0 | 3.55% | 2023-11-01 | 2024-11-21 |
| CVE-2023-33226 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. | [email protected] | 8.0 | 3.55% | 2023-11-01 | 2024-11-21 |
| CVE-2021-35226 | An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role. | [email protected] | 6.5 | 0.32% | 2022-10-10 | 2026-02-24 |
| CVE-2014-3459 | Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEstrarg1 property. | [email protected] | 6.8 | 4.55% | 2014-08-07 | 2026-05-06 |