Lucene search

K
cisa_kevCISACISA-KEV-CVE-2024-28995
HistoryJul 17, 2024 - 12:00 a.m.

SolarWinds Serv-U Path Traversal Vulnerability

2024-07-1700:00:00
CISA
www.cisa.gov
21
solarwinds
serv-u
path traversal
vulnerability
attacker access
sensitive files
host machine

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.959

Percentile

99.5%

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.959

Percentile

99.5%