Cyber Resilience

CVE-2023-33224

Solarwinds Platform ≤ 2023.3.0

Published
26 July 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 7.2
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.028 85th percentile
Risk Priority 57 floored blend · peak EPSS

Summary

CVE-2023-33224 is a high-severity Incorrect Behavior Order (CWE-696) vulnerability in Solarwinds Solarwinds Platform. Its CVSS base score is 7.2 (High).

Operationally, ranked in the top 15% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-45710Same product: Solarwinds Solarwinds Platform
CVE-2023-50395Same product: Solarwinds Solarwinds Platform
CVE-2024-28999Same product: Solarwinds Solarwinds Platform
CVE-2024-52612Same product: Solarwinds Solarwinds Platform
CVE-2024-29003Same product: Solarwinds Solarwinds Platform
CVE-2024-28076Same product: Solarwinds Solarwinds Platform
CVE-2023-40056Same product: Solarwinds Solarwinds Platform
CVE-2024-29004Same product: Solarwinds Solarwinds Platform
CVE-2024-29000Same product: Solarwinds Solarwinds Platform
CVE-2023-40061Same product: Solarwinds Solarwinds Platform

Affected Assets

solarwinds
solarwinds platform
≤ 2023.3.0

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly enforce correct sequencing of security-relevant operations during design and coding.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing can detect ordering flaws but does not prevent them during development.

prevents

Secure development life cycle mandates correct sequencing of security activities, directly preventing incorrect behavior order.

prevents

Secure system architecture and engineering principles require proper ordering of design and implementation steps.

prevents

Secure coding standards enforce correct execution order of security-critical operations.

none

Change management may catch order-related issues during reviews but does not address root cause.

References