Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in SolarWinds Observability Self-Hosted, stemming from inadequate security checks that could allow unauthorized remote code execution. This issue primarily impacts installations that are not configured with default, secure settings, posing a potential risk if exploited. The main concern is confirming whether our specific configurations align with the conditions described, given that such systems are typically managed within internal networks.
- Unauthenticated attackers can run code remotely.
- Affects non-default, insecure SolarWinds configurations.
- Confirm relevance and exposure within our environment.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker could exploit this vulnerability by sending specially crafted data over the network to a SolarWinds Observability Self-Hosted installation. If the installation is not using its default, secure configuration, this could lead to the execution of arbitrary code with high impact on confidentiality, integrity, and availability.
- Unauthenticated network access required.
- Insufficient integrity checks are triggered.
- Remote code execution leads to high impact.
Live Threat
Current exploitation, exposure, and threat context
In installations of SolarWinds Observability Self-Hosted that are not using default, secure configurations, an unauthenticated remote code execution vulnerability could allow an attacker to execute arbitrary code. This means an attacker could potentially take control of the affected system.
- System integrity and data confidentiality.
- Unauthenticated network access.
- Compromise of affected systems.
Operational Fix
Recommended remediation, mitigation, and detection steps
Addressing this critical vulnerability in SolarWinds Observability Self-Hosted likely falls to application owners and platform teams responsible for maintaining the SolarWinds environment. The first practical step is to identify all instances of the affected technology, confirm whether they are exposed externally or are business-critical, and then locate the specific owner for each instance to initiate a risk-based remediation plan.
- Identify application owners and platform teams.
- Verify installation security and exposure.
- Plan remediation based on risk assessment.