HIGH
CVE-2024-28995
CVSS
7.5
KEV
Description
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
Summary dbcve.org
SolarWinds Serv-U contains a directory traversal vulnerability that allows attackers to escape the restricted file system using path traversal sequences (e.g., ../) to access and read sensitive files outside the intended directory scope on the host machine.
Mitigation
Apply the vendor-supplied patch for Serv-U. If no patch is immediately available, restrict network access to the Serv-U service and implement strict input validation on file path parameters to block traversal sequences.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
99.61%
Probability of exploitation in next 30 days
99.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.