CVE-2024-28995
HIGH KEV NUCLEISolarWinds Serv-U - Directory Traversal
Title source: nucleiDescription
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
Exploits (14)
exploitdb
WORKING POC
by İbrahimsql · pythonremotemultiple
https://www.exploit-db.com/exploits/52311
nomisec
WORKING POC
1 stars
by Praison001 · infoleak
https://github.com/Praison001/CVE-2024-28995-SolarWinds-Serv-U
nomisec
SCANNER
1 stars
by huseyinstif · infoleak
https://github.com/huseyinstif/CVE-2024-28995-Nuclei-Template
metasploit
WORKING POC
by sfewer-r7, Hussein Daher · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/solarwinds_servu_fileread_cve_2024_28995.rb
Nuclei Templates (1)
SolarWinds Serv-U - Directory Traversal
HIGHVERIFIEDby DhiyaneshDK
Shodan:
html:"Serv-U"
FOFA:
server="Serv-U"
Scores
CVSS v3
8.6
EPSS
0.9443
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
CISA KEV
2024-07-17
VulnCheck KEV
2024-06-21
InTheWild.io
2024-07-17
ENISA EUVD
EUVD-2024-26057
CWE
CWE-22
Status
published
Products (2)
solarwinds/serv-u
15.4.2 (2 CPE variants)
solarwinds/serv-u
< 15.4.2
Published
Jun 06, 2024
KEV Added
Jul 17, 2024
Tracked Since
Feb 18, 2026