THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-28995

SolarWinds Serv-U L Directory Transversal Vulnerability

Reserved:2024-03-13
Published:2024-06-06
Updated:2024-06-10

Description

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.



HIGH: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
affected

15.4.2 HF 1 and previous versions
affected

Credits

Hussein Daher finder

References

https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28995 vendor-advisory

cve.org CVE-2024-28995

nvd.nist.gov CVE-2024-28995

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-28995