A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.
15.4. SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1.
15.4. SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44667 | A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4. SolarWinds found that the issue was not completely fixed in 15.4 Hotfix 1. |
Fixes
Solution
All SolarWinds Serv-U customers are advised to upgrade to the latest version of the SolarWinds Serv-U version 15.4 Hotfix 2
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2025-02-27T20:57:19.408Z
Reserved: 2023-08-08T23:22:08.619Z
Link: CVE-2023-40060
Updated: 2024-08-02T18:24:54.578Z
Status : Modified
Published: 2023-09-07T16:15:08.227
Modified: 2024-11-21T08:18:37.563
Link: CVE-2023-40060
No data.
OpenCVE Enrichment
No data.
EUVD