MEDIUM
Arbitrary File Overwrite Vulnerability
Published May 3, 2024
5.7
MEDIUMCVSS 3.1
EPSS 0.64%
Description
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
Affected products
-
- Version 15.4.2 and Previous VersionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SolarWinds | Serv-U | affected |
|
OR
- < 15.4.2
- 15.4.2
-
- Version 0StatusaffectedConstraints<=15.4.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SolarWinds | Serv-U | affected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
SolarWinds recommends that customers upgrade to SolarWinds Serv-U version 15.4.2 Hotfix 1 as soon as it becomes available.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-25239 Advisory
- https://solarwindscore.my.site.com/SuccessCenter/s/article/Serv-U-15-4-2-Hotfix-1-Release-Notes?language=en_US Release Notes
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28072 Vendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SolarWinds
Published May 3, 2024
Updated Aug 2, 2024
Reserved Mar 1, 2024
Link CVE-2024-28072
CISA Vulnrichment
Updated May 3, 2024
ENISA EUVD
EUVD-2024-25239 Assigner SolarWinds
Published May 3, 2024
Updated Aug 2, 2024
Exploited since n/a
Link EUVD-2024-25239