SolarWinds Patches Exploited Serv-U Vulnerability

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

The US cybersecurity agency CISA on Friday warned of attacks targeting a SolarWinds Serv-U vulnerability that had been patched a couple of days earlier.

Tracked as CVE-2026-28318 (CVSS score of 7.5), the bug is described as a denial-of-service (DoS) issue that can be exploited via specially crafted POST requests to crash the Serv-U service.

Successful exploitation of the security defect does not require authentication, SolarWinds warned on Thursday.

The flaw was addressed in Serv-U 15.5.4 Hotfix 1. SolarWinds encourages all customers to download and install the hotfix, including those who recently upgraded to Serv-U 15.5.4.

According to SolarWinds, the hotfix prevents attackers from crashing the Serv-U service via requests containing the ‘Content-Encoding: deflate’ header and some data.

Users of Serv-U versions 15.4.2, 15.5, and 15.5.1, which have reached End-of-Life (EoL), are advised to upgrade to a supported release as soon as possible.

Advertisement. Scroll to continue reading.

While SolarWinds’s advisory...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more