HTTP2: SolarWinds Security Event Manager AMF Insecure Deserialization

This signature detects attempts to exploit a known vulnerability against SolarWinds. A successful attack can lead to arbitrary code execution.

Extended Description

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds service, resulting in remote code execution.

Affected Products

Solarwinds security_event_manager

Short Name
HTTP2:SOLAR-WIND-INSC-DES
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP2
Keywords
AMF CVE-2024-0692 Deserialization Event Insecure Manager Security SolarWinds
Release Date
05/14/2024
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3776
False Positive
Unknown
Vendors

Solarwinds

Found a potential security threat?