VYPR
High severity8.6CISA KEVNVD Advisory· Published Jun 6, 2024· Updated Jun 17, 2026

CVE-2024-28995

CVE-2024-28995

Description

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*range: <15.4.2
    • cpe:2.3:a:solarwinds:serv-u:15.4.2:-:*:*:*:*:*:*
    • cpe:2.3:a:solarwinds:serv-u:15.4.2:hotfix1:*:*:*:*:*:*
    • (no CPE)
  • SolarWinds/SolarWinds Serv-Uv5
    Range: 15.4.2 HF 1 and previous versions

Patches

Vulnerability mechanics

References

2

News mentions

2