CVE-2024-28995

SolarWinds Serv-U L Directory Transversal Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
March 13, 2024
Published Date
June 06, 2024
Last Updated
August 02, 2024
Vendor
SolarWinds
Product
SolarWinds Serv-U
Description
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

CVSS Scores

CVSS v3.1

8.6 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (added 2024-07-17 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2024-06-14 08:04:48 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2024-07-17 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

gotr00t0day/CVE-2024-28995

Type: github • Created: 2024-08-24 17:05:48 UTC • Stars: 3

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Stuub/CVE-2024-28995

Type: github • Created: 2024-07-01 11:49:51 UTC • Stars: 34

CVE-2024-28955 Exploitation PoC

bigb0x/CVE-2024-28995

Type: github • Created: 2024-06-14 23:05:40 UTC • Stars: 12

CVE-2024-28995 POC Vulnerability Scanner

0xc4t/CVE-2024-28995

Type: github • Created: 2024-06-14 08:04:48 UTC • Stars: 2

Exploit for CVE-2024-28995

ggfzx/CVE-2024-28995

Type: github • Created: 2024-06-14 07:56:03 UTC • Stars: 2

krypton-kry/CVE-2024-28995

Type: github • Created: 2024-06-14 04:06:58 UTC • Stars: 3

CVE-2024-28995 PoC