QID 378598

Date Published: 2023-07-25

QID 378598: SolarWinds Serv-U Exposure of Sensitive Information Vulnerability

SolarWinds Serv-U Managed File Transfer Server is a versatile, easy-to-deploy solution that integrates well into existing infrastructure. It allows us to meet all our compliance requirements and ensures peace of mind for file transfers.

Affected versions:
Serv-U 15.3.2 and earlier

QID Detection Logic(Authenticated):
This QID checks for the vulnerable version of Serv-U on windows OS

QID Detection Logic(UnAuthenticated):
This QID checks the banner to detect if the device is running vulnerable SolarWinds Serv-U version.

If this vulnerability is exploited, it could allow Exposure of Sensitive Information

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.9 severity.
  • Solution
    For more information about patch and fixes visit Serv-U 15.4 Security Advisory.

    CVEs related to QID 378598

    Software Advisories
    Advisory ID Software Component Link
    cve-2023-23841 URL Logo www.solarwinds.com/trust-center/security-advisories/cve-2023-23841