Junglewise Threat Intelligence

CVE-2024-28995: SolarWinds Serv-U Path Traversal Vulnerability

CVE-2024-28995 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2024-07-17

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U is vulnerable to a directory traversal flaw that allows unauthenticated remote attackers to read sensitive files on the host machine. This vulnerability stems from improper limitation of a pathname to a restricted directory.

Affected products

  • SolarWinds Serv-U up to (excluding) 15.4.2 hotfix 2

Timeline

  • 2024-06-06: disclosed: Initial NVD publication date
  • 2024-06-06: advisory: SolarWinds vendor advisory published
  • 2024-07-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-07-17: exploited: Reported as exploited in the wild by CISA

Related threats