SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Orion_network_performance_monitor | Solarwinds | * | 12.4 (excluding) |