VYPR
Unrated severityNVD Advisory· Published Feb 3, 2021· Updated Aug 4, 2024

CVE-2020-27994

CVE-2020-27994

Description

SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated directory traversal in SolarWinds Serv-U before 15.2.2 allows reading arbitrary files outside the user's home directory.

Vulnerability

SolarWinds Serv-U FTP server versions up to 15.2.1 do not properly validate path information when handling GET requests, allowing an authenticated user to traverse directories outside of their home directory. This path traversal vulnerability is present in the web-based components of the file server. [1]

Exploitation

An attacker must have valid authentication credentials to access the Serv-U FTP server. By crafting a specially crafted GET request containing directory traversal sequences (such as ../), the attacker can navigate outside the restricted user directory and access files and folders otherwise not accessible. No additional privileges or user interaction beyond authentication is required. [1]

Impact

Successful exploitation enables the attacker to read arbitrary files and list directories present on the web server, leading to unauthorized disclosure of sensitive information (e.g., configuration files, system data). The attacker does not achieve code execution or direct write access, but information disclosure may facilitate further compromise. [1]

Mitigation

The vulnerability is fixed in SolarWinds Serv-U version 15.2.2, released on an undisclosed date. Users should upgrade to 15.2.2 or later immediately. There are no known workarounds; updating to the patched version is the only mitigation. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.