Back

CVE-2019-8917

CRITICAL

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.

Published: Feb 18, 2019 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
solarwinds orion_network_performance_monitor * < 12.4

GitHub Security Advisory GHSA-r4f2-fcfp-vm9q

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 36.45%

Top 2% most likely to be exploited

Threat Score 50.1 / 100

Data Sources

NVD EPSS GitHub