Wednesday, May 28, 2025
HomeCVE/vulnerabilitySolarWinds Serv-U Vulnerability Let Attackers Access sensitive files

SolarWinds Serv-U Vulnerability Let Attackers Access sensitive files

Published on

SIEM as a Service

Follow Us on Google News

SolarWinds released a security advisory for addressing a Directory Traversal vulnerability which allows a threat actor to read sensitive files on the host machine.

This vulnerability existed in the SolarWinds Serv-U File Transfer solution and was assigned with CVE-2024-28995 – 8.6 (High).

This vulnerability affected multiple SolarWinds Serv-products in both Windows and Linux platforms.

- Advertisement - Google News

However, it was fixed in the latest version, SolarWinds Serv-U 15.4.2 HF 2. The company also recommends that users upgrade their products to the latest version.

Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot

Technical Analysis – CVE-2024-28995

According to the reports shared with Cyber Security News, this vulnerability affected Server-U FTP server 15.4, Serv-U Gateway 15.4 and Serv-U MFT Server 15.4.

The Serv-U is a C++-written application that contains the majority of the code in the Serv-U.dll binary. 

On analyzing this binary further, it was discovered that there was a modified function sub_18016DC30.

This modified version of this function processes a file path with added checks. The check was written in such a way that it checks particularly for the double dot path segment (\..\) and if found, it is sanitized.

Further investigations concluded that most of this function’s use cases contain two HTTP request parameters, InternalDir and InternalFile, both of which call the vulnerable function. 

However, when providing a directory traversal payload to these parameters on a vulnerable version of Serv-U, the application processed the payload and triggered the directory traversal vulnerability.

This vulnerability can also be modified to reach an arbitrary file on the target server that could reveal sensitive information.

As an added fact, if the Serv-U application is installed on a Windows machine, the system data will be stored in the following path C:\ProgramData\RhinoSoft\Serv-U\.

Further, Serv-U-StartupLog.txt on the system data folder contains the application logging information emitted during application startup and will also include the target Serv-U server’s version number.

On a Linux platform, this vulnerability can be triggered to read.

Users of SolarWinds Serv-U are recommended to upgrade to the latest version or apply the 15.4.2 Hotfix 2 to remediate this vulnerability.

Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Threat Actors Use Fake DocuSign Notifications to Steal Corporate Data

DocuSign has emerged as a cornerstone for over 1.6 million customers worldwide, including 95%...

Government Calls on Organizations to Adopt SIEM and SOAR Solutions

In a landmark initiative, international cybersecurity agencies have released a comprehensive series of publications...

WordPress TI WooCommerce Wishlist Plugin Flaw Puts Over 100,000 Websites at Risk of Cyberattack

A severe security flaw has been identified in the TI WooCommerce Wishlist plugin, a...

Microsoft Alerts on Void Blizzard Hackers Targeting Telecommunications and IT Sectors

Microsoft Threat Intelligence Center (MSTIC) has issued a critical warning about a cluster of...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Use Fake DocuSign Notifications to Steal Corporate Data

DocuSign has emerged as a cornerstone for over 1.6 million customers worldwide, including 95%...

Government Calls on Organizations to Adopt SIEM and SOAR Solutions

In a landmark initiative, international cybersecurity agencies have released a comprehensive series of publications...

WordPress TI WooCommerce Wishlist Plugin Flaw Puts Over 100,000 Websites at Risk of Cyberattack

A severe security flaw has been identified in the TI WooCommerce Wishlist plugin, a...