CVE-2024-28995: high-severity vulnerability in SolarWinds Serv-U
SolarWinds Serv-U L Directory Transversal Vulnerability
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
SolarWinds Serv-U has a flaw that lets attackers bypass directory restrictions and read sensitive files on the server. This is dangerous because it exposes confidential data like configuration files and credentials.
A path traversal vulnerability in SolarWinds Serv-U allows an attacker to use specially crafted input sequences (e.g., ../ patterns) to escape intended directory boundaries and access arbitrary files with the privileges of the Serv-U process. Exploitation requires network access to the Serv-U service; successful exploitation enables unauthorized information disclosure of sensitive files.
The full analysis of this CVE is available in Portuguese →