security1 publisher
SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure
Both Observability Self-Hosted flaws are remotely exploitable without authentication, and both depend on how the deployment was configured. The same researcher reported a third unauthenticated SolarWinds RCE a week earlier.
Publishers:securityweek.com
Reality
- Evidence46
- Adoption22
- Hype gap+12
- Incentives64
- Confidence55