Network Management

CVE-2019-8917 NPM Vulnerability

CVE-2019-8917 NPM Vulnerability

First published date

4/16/2019 3:32 PM

Last published date

6/19/2019 12:13 PM

Overview

SolarWinds internally detected a remote code execution vulnerability with Network Performance Monitor (NPM) in the Orion Platform, specifically in the OrionModuleEngine service. After our internal discovery, this vulnerability was also raised by an analyst per CVE-2019-8917  (© 2019 National Vulnerability Database., available at https://nvd.nist.gov/, obtained on Feb 26, 2019).

Product section

Orion Platform

Cause

  • Known Vulnerability

Resolution

SolarWinds encourages all customers to upgrade to Orion Platform 2018.4 as soon as possible. For the most secure deployment of NPM, we also encourage following best practices for network segmentation and implementation of access controls for relevant servers.