EXECUTIVE SUMMARY:
SolarWinds has issued a security advisory highlighting vulnerabilities affecting its Serv-U and SolarWinds Platform products. The advisory identifies several high-severity flaws, including a Directory Traversal vulnerability (CVE-2024-45711) and an Uncontrolled Search Path Element flaw (CVE-2024-45710), both of which allow attackers to escalate privileges or execute code remotely. Additionally, two Cross-Site Scripting (XSS) vulnerabilities, CVE-2024-45714 and CVE-2024-45715, affect Serv-U and SolarWinds Platform products, respectively, potentially compromising system security. With CVSS scores ranging from 4.8 to 7.8, SolarWinds urges organizations to implement the latest patches and adopt strategies to mitigate risk, including network segmentation, patch management, and continuous monitoring.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
SolarWinds has issued a security advisory highlighting vulnerabilities affecting its Serv-U and SolarWinds Platform products. The advisory identifies several high-severity flaws, including a Directory Traversal vulnerability (CVE-2024-45711) and an Uncontrolled Search Path Element flaw (CVE-2024-45710), both of which allow attackers to escalate privileges or execute code remotely. Additionally, two Cross-Site Scripting (XSS) vulnerabilities, CVE-2024-45714 and CVE-2024-45715, affect Serv-U and SolarWinds Platform products, respectively, potentially compromising system security. With CVSS scores ranging from 4.8 to 7.8, SolarWinds urges organizations to implement the latest patches and adopt strategies to mitigate risk, including network segmentation, patch management, and continuous monitoring.[emaillocker id="1283"]
SolarWinds strongly advises organizations to prioritize patching affected systems and adopt additional security measures, such as network segmentation, monitoring, and a robust incident response plan. Timely action is essential to reduce the risk of these vulnerabilities being exploited in the wild.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://cyble.com/blog/solarwinds-releases-patches-for-high-severity/