vulnerability

SolarWinds Serv-U: CVE-2023-40060: MFA/2FA Bypass Vulnerability in Serv-U 15.4: Serv-U 15.4 and 15.4 HF1

Severity
8
CVSS
(AV:N/AC:M/Au:M/C:C/I:C/A:C)
Published
Aug 30, 2023
Added
Aug 1, 2025
Modified
Aug 1, 2025

Description

A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. The previous vulnerability (CVE-2023-35179) was not completely resolved in 15.4 Hotfix 1.

Solution

solarwinds-serv-u-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.