S4E just found a high-severity finding from cve-2025-58360 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jun 10, 2025

CVE-2024-0692 Scanner

CVE-2024-0692 Scanner - Remote Code Execution vulnerability in SolarWinds Security Event Manager

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-0692
8.8
CVSShigh
Exploitable from an adjacent network · no authentication required.

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

Attack Vector
Adjacent
Privileges Req.
None
User Interaction
None
Affected
Security Event Manager by SolarWinds
2023.4 and previous versions
security_event_managerby solarwinds
AFFECTED< 2023.4SAFE ✓≥ 2023.4
Updated Sep 10, 2026View on NVD →
Detail

SolarWinds Security Event Manager (SEM) is an enterprise-grade Security Information and Event Management (SIEM) platform designed to help organizations monitor, detect, and respond to security threats. It aggregates logs and events from various sources and provides real-time analysis for incident detection and compliance. SEM is commonly used by security operations centers (SOCs) in businesses, government agencies, and managed service providers. It integrates with network devices, endpoints, and applications to correlate events and enforce security policies. Accessible via a web interface, it also provides automated responses and extensive reporting capabilities. Due to its sensitive role, any vulnerability in SEM can severely impact an organization’s security posture.

This scanner detects a remote code execution (RCE) vulnerability in SolarWinds Security Event Manager that allows unauthenticated attackers to execute arbitrary code. The flaw is rooted in the way the application handles AMF (Action Message Format) deserialization on the `/services/messagebroker/streamingamf` endpoint. Unvalidated input sent via crafted AMF payloads can trigger insecure deserialization leading to RCE. Since no authentication is required, the attack surface is exposed to unauthenticated users on the same network. The CVSS score of 8.8 reflects the high impact of this vulnerability on confidentiality, integrity, and availability.

The vulnerable endpoint is `/services/messagebroker/streamingamf`, which accepts AMF-formatted data. By sending a malicious POST request with crafted binary AMF content, an attacker can exploit the insecure deserialization process. This vulnerability is classified under CWE-502 (Deserialization of Untrusted Data), indicating that the input stream is not properly sanitized. The scanner identifies a vulnerable target by first confirming the presence of the SEM interface and then checking for AMF-specific markers in the response. A successful match indicates that the system is processing AMF content and is likely vulnerable to exploitation.

If exploited, this vulnerability enables attackers to execute arbitrary code on the SEM host system, potentially gaining full control. This can lead to the exfiltration of sensitive logs and security data, manipulation of event processing, or insertion of malicious responses. An attacker may also use the SEM infrastructure to pivot to other internal systems. In enterprise environments, this compromises the very system responsible for detecting and responding to threats. Successful exploitation can disrupt security monitoring and blind detection capabilities, resulting in prolonged breaches.

REFERENCES

Solution Advice
  • Update SolarWinds Security Event Manager to version 2023.4.1 or later, which patches the RCE vulnerability.
  • Restrict access to SEM services at the network layer to only trusted IP addresses.
  • Apply input filtering and AMF deserialization hardening on message broker endpoints.
  • Continuously monitor SEM logs and services for signs of suspicious activity or exploitation attempts.
  • Implement strict application-layer firewalls and anomaly detection for SEM web traffic.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

SolarWinds Security Event Manager - Unauthenticated RCE CVE-2024-0692 Scanner | S4E