CVE-2023-33224
The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.13%
- CWE
- CWE-696
- Published
- 2023-07-26
- Last modified
- 2026-03-13
Affected products
- SolarWinds SolarWinds Platform
Weakness type
Related vulnerabilities
- CVE-2026-44108 — Firewall bypass during shutdown
- CVE-2021-31379 — Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
- CVE-2021-22569 — Denial of Service of protobuf-java parsing procedure
- CVE-2025-31485 — GraphQL grant on a property might be cached with different objects
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2024-24853 — Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Process
- CVE-2025-0150 — Zoom Workplace Apps for iOS - Incorrect Behavior Order
- CVE-2026-45033 — GitHub Copilot CLI: Nested Bare Repository Can Execute Arbitrary Commands via core.fsmonitor