Skip to content
COOEY

EXPOSURES › CVE-2024-28995

CVE-2024-28995

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-28995 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatcheddata-breach

SolarWinds Serv-U allows remote attackers to read sensitive files via a path traversal vulnerability.

This path traversal flaw in SolarWinds Serv-U enables attackers to access sensitive host files, posing a significant data exposure risk for DIB organizations relying on SolarWinds infrastructure. The vulnerability is actively exploited in the wild, necessitating immediate patching and network segmentation to prevent unauthorized data access.

Shame score — Active exploitation of a known vulnerability in a widely deployed product indicates a failure in timely patching and security monitoring.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.