SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
CVE-2018-16792 (sftp/scp_server)
Leave a reply
410-897-9494
Receive RedZone Security Updates in Your InboxContact Us
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
You must be logged in to post a comment.