HIGH

CVE-2024-28995

Solarwinds Serv U 2024-06-06 CVSS v3.1
CVSS
7.5
KEV

Description

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Summary dbcve.org

SolarWinds Serv-U contains a directory traversal vulnerability that allows attackers to escape the restricted file system using path traversal sequences (e.g., ../) to access and read sensitive files outside the intended directory scope on the host machine.

Mitigation

Apply the vendor-supplied patch for Serv-U. If no patch is immediately available, restrict network access to the Serv-U service and implement strict input validation on file path parameters to block traversal sequences.

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

99.61%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE