CyberzSOC

Publication detail
← Back to advisories & guidance

2024-055: SolarWinds High-Severity Vulnerabilities ↗ source

June 8, 2024 CERT-EU Advisory

Summary

CERT-EU strongly recommends patching them as soon as possible. CVE-2024-28995 - SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine [2]. CVE-2024-28996 - The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. CVE-2024-28999 - The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console [4]. CVE-2024-29004 - The SolarWinds Platform was determined to be affected by a stored crosssite scripting vulnerability affecting the web console.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-28995 8.6 High SolarWinds Serv-U SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.
CVE-2024-28996 7.5 High SolarWinds SolarWinds Platform The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.  
CVE-2024-29004 7.1 High SolarWinds SolarWinds Platform The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged use…
CVE-2024-28999 6.4 Medium SolarWinds SolarWinds Platform The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.