KEVIntel
8.6
CVSS
High

CVE-2024-28995

PUBLISHED

SolarWinds Serv-U L Directory Transversal Vulnerability

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
SolarWinds
Product
SolarWinds Serv-U
Published
Jun 06, 2024
EPSS

Description

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

windows cisa nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 8.6 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2024-07-17 00:00:00 UTC · Source

Proof of concept available

Recorded 2024-06-14 08:04:48 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jul 17, 2024

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

gotr00t0day/CVE-2024-28995

github · Created 2024-08-24 17:05:48 UTC · 3 stars

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Stuub/CVE-2024-28995

github · Created 2024-07-01 11:49:51 UTC · 34 stars

CVE-2024-28955 Exploitation PoC

bigb0x/CVE-2024-28995

github · Created 2024-06-14 23:05:40 UTC · 12 stars

CVE-2024-28995 POC Vulnerability Scanner

0xc4t/CVE-2024-28995

github · Created 2024-06-14 08:04:48 UTC · 2 stars

Exploit for CVE-2024-28995

ggfzx/CVE-2024-28995

github · Created 2024-06-14 07:56:03 UTC · 2 stars

krypton-kry/CVE-2024-28995

github · Created 2024-06-14 04:06:58 UTC · 3 stars

CVE-2024-28995 PoC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Nuclei