Rewterz
Earth Preta aka Mustang Panda APT Group – Active IOCs
June 10, 2024
Rewterz
Sticky Werewolf Launches Cyberattacks Targeting Belarus and Russia – Active IOCs
June 10, 2024

Multiple SolarWinds Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-28999 CVSS:6.4

SolarWinds Platform could allow a remote attacker to obtain sensitive information, caused by a race condition in the Web console. An attacker could exploit this vulnerability to obtain sensitive information.

CVE-2024-28995 CVSS:8.6

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Impact

  • Gain Access
  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2024-28999
  • CVE-2024-28995

Affected Vendors

SolarWinds

Affected Products

  • SolarWinds Platform 2024.1.1 and previous versions
  • SolarWinds Serv-U 15.4.2 HF 1 and previous versions

Remediation

Upgrade to the latest version of SolarWinds Products, available from the SolarWinds Website.

CVE-2024-28999

CVE-2024-28995