Lucene search

K
cvelistSolarWindsCVELIST:CVE-2024-28995
HistoryJun 06, 2024 - 9:01 a.m.

CVE-2024-28995 SolarWinds Serv-U L Directory Transversal Vulnerability

2024-06-0609:01:23
CWE-22
SolarWinds
www.cve.org
25
solarwinds
serv-u
directory transversal
vulnerability
sensitive files
host machine

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

8.4

Confidence

High

EPSS

0.959

Percentile

99.5%

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "SolarWinds Serv-U ",
    "vendor": "SolarWinds ",
    "versions": [
      {
        "status": "affected",
        "version": "15.4.2 HF 1 and previous versions"
      }
    ]
  }
]

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

AI Score

8.4

Confidence

High

EPSS

0.959

Percentile

99.5%