QID 376489

Date Published: 2022-03-23

QID 376489: SolarWinds Serv-U Directory Transversal Vulnerability

SolarWinds Serv-U Managed File Transfer Server is a versatile, easy-to-deploy solution that integrates well into existing infrastructure. It allows us to meet all our compliance requirements and ensures peace of mind for file transfers.

Affected versions:
Only Serv-U version 15.3

QID Detection Logic(Authenticated):
This QID checks for the vulnerable version of Serv-U on windows OS

QID Detection Logic(UnAuthenticated):
This QID checks the banner to detect if the device is running vulnerable SolarWinds Serv-U version.

If this vulnerability is exploited, it could allow access to files relating to the Serv-U installation and server files.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to apply the HotFix, Serv-U 15.3 Hotfix 1 available on the vendor's website.
    For more information about patch and fixes visit Serv-U 15.3 Security Advisory.
    Vendor References

    CVEs related to QID 376489

    Software Advisories
    Advisory ID Software Component Link
    Serv-U 15.3 HotFix 1 URL Logo support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-3-HotFix-1?language=en_US