Back
CVE-2019-8917
CRITICAL
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.
Published: Feb 18, 2019
Modified: Jun 17, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| solarwinds | orion_network_performance_monitor | * < 12.4 |
GitHub Security Advisory GHSA-r4f2-fcfp-vm9q
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the...
References (4)
- http://www.securityfocus.com/bid/107061 Third Party Advisory, VDB Entry
- https://github.com/VerSprite/research/blob/master/advisories/VS-2019-001.md Third Party Advisory
- http://www.securityfocus.com/bid/107061 Third Party Advisory, VDB Entry
- https://github.com/VerSprite/research/blob/master/advisories/VS-2019-001.md Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
36.45%
Top 2% most likely to be exploited
Threat Score
50.1 / 100
Data Sources
NVD
EPSS
GitHub