CVE CVE

CVE-2024-28995

CISA Known Exploited Vulnerability (KEV)

SolarWinds Serv-U Path Traversal Vulnerability

July 17, 2024

August 7, 2024

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Weakness Enumeration

CWE-ID CWE Name

CWE-22
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)

Known Affected Software Configurations


cpe:2.3:a:solarwinds:serv-u:15.4.0:hotfix2:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.3.0:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.4.0:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.4.0:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.3:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.3:hotfix2:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.2:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.6:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.6:hotfix2:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.6:hotfix3:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.7:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.7:hotfix2:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.7:hotfix3:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.7:hotfix4:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.7:hotfix5:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.1:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.2:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.3:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.4:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.5:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.7:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.3.2:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.3.1:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.3:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.3:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.2.5:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.2.4:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.2.3:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.2.3:hotfix1:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.2.2:-:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.2.1:*:*:*:*:*:*:*

cpe:2.3:a:solarwinds:serv-u:15.1.6:*:*:*:*:*:*:*

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
7.5
Severity:

HIGH

Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2

Not defined