SolarWinds Serv-U has had two high-impact classes. A directory-traversal flaw in its web interface let an attacker read arbitrary files from the host, disclosing configuration and credentials. Separately, memory-corruption in its SSH and file-transfer handling allowed remote code execution. Both are reached over the internet-facing transfer and management interfaces.
Serv-U flaw classes:
- Web-interface directory traversal -> arbitrary file read (configs, secrets)
- Memory corruption in SSH/file-transfer handling -> remote code execution
Exploitation notes#
- The traversal read is a quiet way to pull the server's configuration and stored credentials before any louder action.
- The RCE paths target the SSH and transfer services, so the exposed ports beyond the web console matter.
- Identify the Serv-U version from its banners and interface; the chain here is the MFT-context summary.