First published: Fri May 03 2024(Updated: )
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U FTP Server | <15.4.2 | |
SolarWinds Serv-U FTP Server | =15.4.2 |
SolarWinds recommends that customers upgrade to SolarWinds Serv-U version 15.4.2 Hotfix 1 as soon as it becomes available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28072 is classified as a high-severity vulnerability due to the risk of privileged accounts overwriting arbitrary files on the system.
To fix CVE-2024-28072, it is recommended to upgrade to SolarWinds Serv-U version 15.4.2 Hotfix 1 or later.
CVE-2024-28072 affects users of SolarWinds Serv-U FTP Server versions prior to 15.4.2 Hotfix 1.
In CVE-2024-28072, a highly privileged account can overwrite arbitrary files, potentially leading to critical data loss or system compromise.
The potential impacts of CVE-2024-28072 include unauthorized data modification, data loss, and potential system instability.