Threat Advisory

Active Exploitation of SolarWinds Serv-U Path Traversal Vulnerability

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical vulnerability, CVE-2024-28995, affecting SolarWinds Serv-U products including FTP Server, Gateway, and MFT Server has been rapidly manipulated by threat actors. This high-severity flaw allows attackers to perform directory traversal attacks, enabling unauthorized access to sensitive files on affected systems through crafted HTTP GET requests. Exploitation of CVE-2024-28995 poses significant risks, potentially leading to data exposure and further compromise of affected networks. Attackers have demonstrated various techniques, including manual and automated methods, targeting files such as 'passwd' on Linux and 'win.ini' on Windows system. It is strongly advised to immediately apply the available security updates to mitigate this vulnerability and prevent potential breaches.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A critical vulnerability, CVE-2024-28995, affecting SolarWinds Serv-U products including FTP Server, Gateway, and MFT Server has been rapidly manipulated by threat actors. This high-severity flaw allows attackers to perform directory traversal attacks, enabling unauthorized access to sensitive files on affected systems through crafted HTTP GET requests. Exploitation of CVE-2024-28995 poses significant risks, potentially leading to data exposure and further compromise of affected networks. Attackers have demonstrated various techniques, including manual and automated methods, targeting files such as 'passwd' on Linux and 'win.ini' on Windows system. It is strongly advised to immediately apply the available security updates to mitigate this vulnerability and prevent potential breaches.[emaillocker id="1283"]

RECOMMENDATION:

  • We strongly recommend you update SolarWinds Serv-U to version 15.4.2.157.

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/solarwinds-serv-u-path-traversal-flaw-actively-exploited-in-attacks/

[/emaillocker]
crossmenu