Rapid7 Vulnerability & Exploit Database

SolarWinds Serv-U Unauthenticated Arbitrary File Read

Back to Search

SolarWinds Serv-U Unauthenticated Arbitrary File Read



This module exploits an unauthenticated file read vulnerability, due to directory traversal, affecting SolarWinds Serv-U FTP Server 15.4, Serv-U Gateway 15.4, and Serv-U MFT Server 15.4. All versions prior to the vendor supplied hotfix "15.4.2 Hotfix 2" (version are affected.


  • sfewer-r7
  • Hussein Daher


Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use auxiliary/gather/solarwinds_servu_fileread_cve_2024_28995
msf auxiliary(solarwinds_servu_fileread_cve_2024_28995) > show actions
msf auxiliary(solarwinds_servu_fileread_cve_2024_28995) > set ACTION < action-name >
msf auxiliary(solarwinds_servu_fileread_cve_2024_28995) > show options
    ...show and set options...
msf auxiliary(solarwinds_servu_fileread_cve_2024_28995) > run 

Time is precious, so I don’t want to do something manually that I can automate. Leveraging the Metasploit Framework when automating any task keeps us from having to re-create the wheel as we can use the existing libraries and focus our efforts where it matters.

– Jim O’Gorman | President, Offensive Security