SolarWinds fixes severe Serv-U vulnerability (CVE-2024-28995)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-28995 | Unauthenticated Path Traversal File-Read in SolarWinds Serv-U CVE-2024-28995 is a directory traversal flaw (CWE-22) in SolarWinds Serv-U, the vendor's managed file transfer/FTP server. Per the CVSS vector, it is reachable over the network with low attack complexity and requires no privileges or user interaction, meaning an unauthenticated remote attacker can trigger it. By sending traversal sequences that escape the intended directory, the attacker gains the ability to read sensitive files on the host machine (high confidentiality impact, with no integrity or availability impact). Any organization running SolarWinds Serv-U is potentially affected, particularly instances exposed to the internet. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17, threat actors were reported exploiting it in the wild, and EPSS puts the 30-day exploitation probability at 99.6%, although no public proof-of-concept is known. Do: Apply SolarWinds' patch or hotfix for Serv-U per the vendor's July 2024 PSIRT advisory, prioritizing internet-facing instances; if mitigations cannot be applied, CISA's required action is to follow vendor instructions or discontinue use of the product. In the meantime, restrict Serv-U exposure to trusted networks and review FTP/web server access logs for traversal-style requests that could indicate file reads or exfiltration. | 7.5 | 100% | KEV |
| largelow tens of thousands of internet-exposed Serv-U file-transfer servers |
Full article283 words · extracted from helpnetsecurity.com · click to collapse
SolarWinds has fixed a high-severity vulnerability (CVE-2024-28995) affecting its Serv-U managed file transfer (MFT) server solution, which could be exploited by unauthenticated attackers to access sensitive files on the host machine.

About CVE-2024-28995
Serv-U MFT Server is a widely used enterprise solution that provides secure file transfer and file sharing hosted on Windows and Linux machines.
Discovered and reported by Hussein Daher, CVE-2024-28995 is a directory traversal (aka path traversal) vulnerability that affects SolarWinds Serv-U 15.4.2 HF 1 and previous versions.
Directory traversal vulnerabilities allow attackers to access directories and files outside the server’s root directory.
The vulnerability’s CVSS base score indicates that it can be exploited remotely, through a low-complexity attack, and that no user interaction is required to leverage it.
SolarWinds fixed the flaw by releasing Serv-U 15.4.2 Hotfix 2, which is suitable for both Windows and Linux OSes (whether 32-bit or 64-bit), the company says. Admins are advised to update their Serv-U instances as soon as possible.
There is no mention of the bug being actively exploited, but attacker have been known to leverage Serv-U vulnerabilities (including zero-days).
UPDATE (June 14, 2024, 04:50 a.m. ET):
The vulnerability is “trivially exploitable”, according to Rapid7.
They managed to exploit the vulnerability on a Windows Server 2022 system running SolarWinds Serv-U File Server (64-bit) version 15.4.2.126, and on Serv-U File Server (64-bit) version 15.4.2.126 running on Linux, and have verified that Solarwind’s hotfix remediates the flaw.
UPDATE (June 19, 2024, 03:50 a.m. ET):
Ron Bowes, Lead Security Researcher at GreyNoise Labs, has detailed CVE-2024-28995 exploitation attempts against their honeypots.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/06/07/cve-2024-28995/