Network Management

SolarWinds Network Topology Mapper and CVE-2018-1285

Network Topology Mapper uses an older version of log4net that is vulnerable under certain conditions. SolarWinds deems the risk of the vulnerability low based on our security review.

First published date

11/29/2023 8:48 AM

Last published date

11/29/2023 8:48 AM

Overview

Network Topology Mapper uses an older version of log4net that is vulnerable under certain conditions.
SolarWinds deems the risk of the vulnerability low based on our security review.

Product section

Network Topology Mapper

Cause

CVE-2018-1285

Resolution


Network Topology Mapper is installed locally on the computer, and it doesn’t have the same risk as a
public-facing server. The user would need local access to the machine to pass the vulnerable xml file.
Based on our review, our amended score related to this vulnerability is 4.4 (Moderate). See NVD - CVSS
v3 Calculator (nist.gov)
for details.