First published: Wed Dec 06 2023(Updated: )
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U FTP Server | =15.4.0 | |
SolarWinds Serv-U FTP Server | =15.4.0-hotfix1 | |
SolarWinds Serv-U FTP Server | =15.4.0-hotfix2 |
SolarWinds advises to upgrade to the latest version of Serv-U 15.4.1 once became generally available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40053 has been rated as a significant security vulnerability due to its potential for authenticated exploitation.
To fix CVE-2023-40053, update to the latest version of Serv-U, which includes security patches addressing this vulnerability.
CVE-2023-40053 can allow an authenticated actor to maliciously insert content through the file share function.
CVE-2023-40053 affects Serv-U 15.4.0 and its hotfix versions 15.4.0-hotfix1 and 15.4.0-hotfix2.
Organizations using the affected versions of Serv-U are at risk due to the vulnerability allowing potentially harmful actions by authenticated users.