Threat Advisory

SolarWinds Urges Immediate Patching for High-Severity Vulnerabilities

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

SolarWinds has issued a security advisory highlighting vulnerabilities affecting its Serv-U and SolarWinds Platform products. The advisory identifies several high-severity flaws, including a Directory Traversal vulnerability (CVE-2024-45711) and an Uncontrolled Search Path Element flaw (CVE-2024-45710), both of which allow attackers to escalate privileges or execute code remotely. Additionally, two Cross-Site Scripting (XSS) vulnerabilities, CVE-2024-45714 and CVE-2024-45715, affect Serv-U and SolarWinds Platform products, respectively, potentially compromising system security. With CVSS scores ranging from 4.8 to 7.8, SolarWinds urges organizations to implement the latest patches and adopt strategies to mitigate risk, including network segmentation, patch management, and continuous monitoring.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

SolarWinds has issued a security advisory highlighting vulnerabilities affecting its Serv-U and SolarWinds Platform products. The advisory identifies several high-severity flaws, including a Directory Traversal vulnerability (CVE-2024-45711) and an Uncontrolled Search Path Element flaw (CVE-2024-45710), both of which allow attackers to escalate privileges or execute code remotely. Additionally, two Cross-Site Scripting (XSS) vulnerabilities, CVE-2024-45714 and CVE-2024-45715, affect Serv-U and SolarWinds Platform products, respectively, potentially compromising system security. With CVSS scores ranging from 4.8 to 7.8, SolarWinds urges organizations to implement the latest patches and adopt strategies to mitigate risk, including network segmentation, patch management, and continuous monitoring.[emaillocker id="1283"]

 

  • CVE-2024-45714 (Cross-Site Scripting): A medium-severity flaw affecting Serv-U version 15.4.2.3 and earlier, allowing authenticated attackers to modify variables using malicious payloads.
  • CVE-2024-45711 (Directory Traversal): A high-severity vulnerability impacting Serv-U version 15.4.2 and earlier, allowing authenticated users to execute remote code.
  • CVE-2024-45710 (Uncontrolled Search Path Element): A high-severity flaw in SolarWinds Platform version 2024.2.1 and earlier, enabling local privilege escalation.
  • CVE-2024-45715 (Cross-Site Scripting): A high-severity issue affecting SolarWinds Platform version 2024.2.1 and earlier, enabling XSS attacks during the editing of system elements.

 

SolarWinds strongly advises organizations to prioritize patching affected systems and adopt additional security measures, such as network segmentation, monitoring, and a robust incident response plan. Timely action is essential to reduce the risk of these vulnerabilities being exploited in the wild.

RECOMMENDATION:

  • We strongly recommend you upgrade Serv-U to version 15.5 and SolarWinds Platform to version 2024.4

REFERENCES:

The following reports contain further technical details:
https://cyble.com/blog/solarwinds-releases-patches-for-high-severity/

[/emaillocker]
crossmenu