SolarWinds Serv-U path-traversal flaw actively exploited in attacks
ID: 0c8ac017-17d2-56ad-8f7e-c2b1c03625e8
STIX ID: report--0c8ac017-17d2-56ad-8f7e-c2b1c03625e8
Feed Name: Bleeping Computer
Threat Score
The report describes active exploitation of a high-severity SolarWinds Serv-U directory traversal vulnerability (CVE-2024-28995) that permits unauthenticated arbitrary file reads. Public PoC code and bulk scanners have been released, Rapid7 and GreyNoise observed exploitation attempts targeting files such as /etc/passwd and win.ini, and SolarWinds issued Hotfix 15.4.2.157—administrators are urged to apply the update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
