CVE-2024-28995
Serv-U Managed File Transfer Server vulnerability analysis and mitigation

Overview

CVE-2024-28995 is a high-severity directory traversal vulnerability affecting SolarWinds Serv-U file transfer server (both Serv-U FTP and Serv-U MFT editions). The vulnerability was discovered by Hussein Daher and disclosed by SolarWinds on June 5, 2024. The vulnerability affects SolarWinds Serv-U 15.4.2 HF 1 and previous versions (SolarWinds Advisory, Rapid7).

Technical details

The vulnerability is a directory traversal issue that allows unauthenticated attackers to read any file on the target server's disk, including binary files, provided they know the path and the file is not locked by another process. The vulnerability has been assigned a CVSS v3.1 base score of 8.6 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N. Internet exposure estimates for SolarWinds Serv-U vary between 5,434 and 9,470 instances (Rapid7).

Impact

Successful exploitation of this vulnerability allows attackers to read sensitive files on the host machine. This high-severity information disclosure issue can be used in smash-and-grab attacks where adversaries gain access to and attempt to quickly exfiltrate data from file transfer solutions with the goal of extorting victims (Rapid7).

Exploitability

The vulnerability is trivially exploitable and allows an external unauthenticated attacker to read any file on disk. As of July 17, 2024, the vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild (Rapid7).

Mitigation and workarounds

SolarWinds has released a fix in version 15.4.2 HF 2. Organizations are strongly advised to apply the vendor-provided hotfix immediately, without waiting for a regular patch cycle. CISA has set a due date of August 7, 2024, for federal agencies to apply the mitigations (NVD, Rapid7).

Community reactions

Security researchers have been actively monitoring exploit attempts through honeypots, revealing patterns in attacker behavior and the specific files being targeted. The vulnerability has garnered significant attention from the security community due to its trivial exploitability and potential impact (GreyNoise).

Additional resources


SourceThis report was generated using AI

Related Serv-U Managed File Transfer Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28321CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28317CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28316CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28314CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28315MEDIUM6.2
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management