Security researchers recently discovered that hackers were actively exploiting the SolarWinds Serv-U vulnerability, CVE-2024-28995.
See also: SolarWinds: Fixes vulnerabilities in Access Rights Manager (ARM)

SolarWinds is a leading software company specializing in IT management and monitoring solutions for networks and infrastructure. The company gained notoriety after a major attack in 2020, where hackers injected malicious code into Orion updates, compromising the networks of more than 30,000 customers.
Researchers at GreyNoise Labs recently discovered that hackers were actively exploiting the SolarWinds Serv-U vulnerability CVE-2024-28995.
In June 2024, SolarWinds' file transfer product "Serv-U" was found to have a "critical path-traversal" vulnerability.
This flaw allowed attackers to read arbitrary files by manipulating the “InternalDir” and “InternalFile” parameters in “HTTP” requests. A honeypot that mimics this vulnerability was deployed to study exploitation attempts.
Over a three-month period, the honeypot recorded various attack patterns, starting with basic probes such as “Linux” and “Windows” access , and appearing attempts targeting sensitive files such as “ unattended.xml ” and “ sysprep.xml ,” which may contain plaintext credentials.
See also: SolarWinds: Fixes critical vulnerability in Web Help Desk
Threat actors also searched for “Windows registry hives” (SAM for password data) and “cloud service credentials” for “AWS”, “Azure” and “Google Cloud”.

In addition, Linux systems were initially targeted, and Windows became the primary target, according to the GreyNoise report. Attacks evolved from simple vulnerability scans to intense exploitation attempts.
While the URL encoding and character set differ across payloads, they indicate the different origins of the attackers. The frequency and variety of exploits have decreased over time, indicating decreased interest by threat actors or improved remediation by potential targets.
Furthermore, useful information about the life cycle and exploitation patterns of a “high-profile vulnerability” in a widely used “enterprise software product” is provided by this real-world data.
See also: SolarWinds fixes 8 critical software bugs
This analysis examines file infiltration attempts by attackers targeting a SolarWinds Serv-U server vulnerability, categorizing the requested files into groups such as “scanners,” “Windows credentials,” “web layouts,” “databases,” and “miscellaneous files of interest.”.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
