SolarWinds Patches Exploited Serv-U Vulnerability

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

The US cybersecurity agency CISA on Friday warned of attacks targeting a SolarWinds Serv-U vulnerability that had been patched a couple of days earlier.

Tracked as CVE-2026-28318 (CVSS score of 7.5), the bug is described as a denial-of-service (DoS) issue that can be exploited via specially crafted POST requests to crash the Serv-U service.

Successful exploitation of the security defect does not require authentication, SolarWinds warned on Thursday.

The flaw was addressed in Serv-U 15.5.4 Hotfix 1. SolarWinds encourages all customers to download and install the hotfix, including those who recently upgraded to Serv-U 15.5.4.

According to SolarWinds, the hotfix prevents attackers from crashing the Serv-U service via requests containing the ‘Content-Encoding: deflate’ header and some data.

Users of Serv-U versions 15.4.2, 15.5, and 15.5.1, which have reached End-of-Life (EoL), are advised to upgrade to a supported release as soon as possible.

Advertisement. Scroll to continue reading.

While SolarWinds’s advisory...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE