PublicCVE

CVE-2025-40549

CRITICAL9.1Path traversal

Description

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected products

  • SolarWinds / Serv-USolarWinds Serv-U 15.5.2 and prior versions – SolarWinds Serv-U 15.5.2 and prior versions