EXPOSURES › CVE-2024-28995
CVE-2024-28995
HIGH ⌖ ON CISA KEV · EXPLOITEDSolarWinds Serv-U allows remote attackers to read sensitive files via a path traversal vulnerability.
This path traversal flaw in SolarWinds Serv-U enables attackers to access sensitive host files, posing a significant data exposure risk for DIB organizations relying on SolarWinds infrastructure. The vulnerability is actively exploited in the wild, necessitating immediate patching and network segmentation to prevent unauthorized data access.
Shame score — Active exploitation of a known vulnerability in a widely deployed product indicates a failure in timely patching and security monitoring.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.