SolarWinds Security Update – 18 April 2024

SolarWinds has released a security update to address a vulnerability affecting SolarWinds Serv-U 15.4.1.128 and prior versions.

The addressed vulnerability could allow the remote attacker to execute arbitrary code and gain access to the affected system.

SolarWinds Serv-U Directory Traversal Vulnerability (CVE-2024-28073):

  • CVSS: 8.4
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: Required
  • Consequences: Gain Access
Vulnerabilities

CVE-2024-28073

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

SolarWinds Security Advisory

References