HomeSecuritySolarWinds: Patches Vulnerability Reported by NATO Pentester

SolarWinds: Patches Vulnerability Reported by NATO Pentester

SolarWinds this week announced patches for multiple high - severity vulnerabilities in Serv-U, including an issue reported by a penetration tester working with NATO .

SolarWinds

The 2024.2 version of the SolarWinds platform includes code updates for three new security vulnerabilities and fixes for many third‑party bugs. The first issue, CVE‑2024‑28996, reported by Nils Putnins of the NATO Communications and Information Agency, is described as an SWQL injection flaw. SWQL, a read‑only subset of SQL, allows users to query the SolarWinds database for network information.

Read also: PHP: Fix for vulnerability affecting all Windows versions

SolarWinds also released patches for two security in the platform's web console: CVE-2024-28999, a race condition vulnerability, and CVE-2024-29004, a stored XSS flaw that requires elevated privileges and user interaction to exploit.

According to the company, the vulnerabilities affect version 2024.1 SR 1 and previous versions of the SolarWinds platform. Users are urged to update to version 2024.2 as soon as possible.

The new release also includes fixes for a medium severity flaw in Angular and ten high and medium severity issues in OpenSSL, some of which were disclosed seven years ago. Most of these issues could be used to cause DoS.

This week, SolarWinds released a hotfix for CVE-2024-28995, a high-severity vulnerability in Serv-U that could allow hackers to read sensitive files on the host. With a CVSS score of 8.6, the flaw affects Serv-U hotfix version 15.4.2 and all previous versions, including Serv-U FTP Server, Serv-U Gateway, and Serv-U MFT Server.

SolarWinds

See more: Critical vulnerabilities in WooCommerce Amazon Affiliates plugin

The Serv-U 15.4.2 hotfix resolves the flaw and is compatible with Windows and Linux. SolarWinds says that none of these vulnerabilities have been reported to be exploited at this time. Users and administrators are advised to apply the available patches as soon as possible.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS