CVE-2024-28995
KEVlarge1Unauthenticated Path Traversal File-Read in SolarWinds Serv-U
CISA: SolarWinds Serv-U Path Traversal Vulnerability
CVE-2024-28995 is a directory traversal flaw (CWE-22) in SolarWinds Serv-U, the vendor's managed file transfer/FTP server. Per the CVSS vector, it is reachable over the network with low attack complexity and requires no privileges or user interaction, meaning an unauthenticated remote attacker can trigger it. By sending traversal sequences that escape the intended directory, the attacker gains the ability to read sensitive files on the host machine (high confidentiality impact, with no integrity or availability impact). Any organization running SolarWinds Serv-U is potentially affected, particularly instances exposed to the internet. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17, threat actors were reported exploiting it in the wild, and EPSS puts the 30-day exploitation probability at 99.6%, although no public proof-of-concept is known.
What to do: Apply SolarWinds' patch or hotfix for Serv-U per the vendor's July 2024 PSIRT advisory, prioritizing internet-facing instances; if mitigations cannot be applied, CISA's required action is to follow vendor instructions or discontinue use of the product. In the meantime, restrict Serv-U exposure to trusted networks and review FTP/web server access logs for traversal-style requests that could indicate file reads or exfiltration.
| SolarWinds Serv-U | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
- Affected
- SolarWinds Serv-U
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- solarwinds
- Products
- serv-u
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N