Hackers are actively exploiting a path-traversal in SolarWinds Serv-U, leveraging publicly available PoCs.
See also: Cleveland City Hall: Still closed after ransomware attack

Although the attacks do not appear particularly sophisticated, the observed activity highlights the risk posed by unpatched end points, emphasizing the urgent need for administrators to apply security updates.
The CVE-2024-28995 vulnerability
The vulnerability, CVE-2024-28995, is a high-severity directory traversal flaw that allows unauthenticated attackers to read arbitrary files from the system by crafting specific HTTP GET requests.
The vulnerability arises from insufficient validation of path-traversal sequences, allowing attackers to bypass security checks and access sensitive files.
The vulnerability affects the following SolarWinds products:
- Serv-U FTP Server 15.4
- Serv-U Gateway 15.4
- Serv-U MFT Server 15.4
- Serv-U File Server 15.4.2.126 and earlier versions
Older versions (15.3.2 and earlier) are also affected, but will reach end‑of‑life in February 2025 and are not supported.
See also: Public bus service TheBus victim of ransomware attack?

The exploitation of the vulnerability can expose sensitive data to unauthorized file access, potentially leading to extensive breach.
SolarWinds released hotfix 15.4.2, version 15.4.2.157, on June 5, 2024, to address this vulnerabilityby introducing improved validation mechanisms.
Over the weekend, Rapid7 analysts published a technical write-up that provided detailed steps for exploiting the flaw in SolarWinds Serv-U to read arbitrary files from the affected system.
A day later, an independent Indian researcher released a PoC exploit and a bulk scanner for CVE-2024-28995 on GitHub.
On Monday, Rapid7 warned about how easy it is to exploit the flaw, estimating the number of servers exposed online that are vulnerable at between 5,500 and 9,500.
See also: London hospitals cancel operations after ransomware attack
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Cyberattacks have become an increasingly prevalent threat in our digitally connected world. These malicious activities can range from phishing and ransomware to more sophisticated attacks such as advanced persistent threats (APTs). The consequences of cyberattacks can be severe, affecting individuals, businesses and governments alike. Financial losses, data breaches and compromised personal information are just some of the potential damages. To combat these threats, rigorous cybersecurity measures, continuous monitoring and user education. As technology evolves, so do our strategies for defending against the ever-changing cyber threat landscape.
Source: bleepingcomputer
