Back to Database
Status published
Medium
CVE-2024-28072
Arbitrary File Overwrite Vulnerability
Vulnerability Description
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28072
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Alexander Skovsende at the Institute for Cyber Risk
References
More from SolarWinds
View All →CVE-2024-29004
SolarWinds Platform Stored XSS Vulnerability
High
7.1
CVE-2024-29003
SolarWinds Platform Cross Site Scripting Vulnerability
High
7.5
CVE-2024-29001
SolarWinds Platform SWQL Injection Vulnerability
High
7.5
CVE-2024-28999
SolarWinds Platform Race Condition Vulnerability
Medium
6.4
CVE-2024-28076
SolarWinds Platform Arbitrary Open Redirection Vulnerability
High
7
Affected Vendor
SolarWinds
View all reports →Affected Software
Serv-U
Vulnerable Versions:
15.4.2 and Previous Versions
Timeline
Official Publish:
May 3rd, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L