CVE-2023-40055: SolarWinds Network Configuration Manager

High severity, CVSS 8.8. EPSS: 2.1% chance of exploitation in the next 30 days.

The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227

Affected products

  • SolarWinds Network Configuration Manager: up to and including 2023.4

Published 2023-11-09. Last modified 2026-06-17.