PT-2019-9199 · Solarwinds · Solarwinds Serv-U Ftp Server
Chris Moberly
·
Published
2019-03-17
·
Updated
2019-10-03
·
CVE-2018-15906
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SolarWinds Serv-U FTP Server version 15.1.6
Description
The issue allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
Recommendations
For SolarWinds Serv-U FTP Server version 15.1.6, consider disabling the Import feature as a temporary workaround until a patch is available. Restrict access to the Import feature to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solarwinds Serv-U Ftp Server