Critical severity9.1NVD Advisory· Published Dec 5, 2018· Updated Jun 17, 2026
CVE-2018-16792
CVE-2018-16792
Description
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
Affected products
2<=2018-09-10+ 1 more
- (no CPE)range: <=2018-09-10
- cpe:2.3:a:solarwinds:sftp\/scp_server:*:*:*:*:*:*:*:*range: <=2018-09-10
Patches
Vulnerability mechanics
References
1- seclists.org/fulldisclosure/2018/Dec/0nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.