Vulnerability record · CVE-2010-2115 · published 28 May 2010
CVE-2010-2115: SolarWinds TFTP Server crafted read request denial of service
Solarwinds · Tftp Server
SolarWinds TFTP Server 10.4.0.10 fails to properly validate input in a read request, allowing a remote attacker to exhaust the service so it accepts no new connections. The flaw is a denial of service in a network-facing service, and the record does not state whether a fix or updated version exists.
Description
SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityThe flaw is an unauthenticated remote denial of service with a public exploit and high EPSS, but it only affects availability and the record does not confirm an available patch.
What it is
SolarWinds TFTP Server 10.4.0.10 fails to properly validate input in a read request, allowing a remote attacker to exhaust the service so it accepts no new connections. The flaw is a denial of service in a network-facing service, and the record does not state whether a fix or updated version exists.
Impact
An attacker can render the TFTP service unavailable, blocking legitimate file transfers and any dependent provisioning or configuration workflows. No confidentiality or integrity impact is described; only availability is affected.
Attack surface
Reachable over the network via the TFTP service port with no authentication required, per the AV:N/AC:L/Au:N vector. No user interaction is indicated.
Exploitation
A public exploit exists (Exploit-DB reference), but the CVE is not in CISA KEV and no ransomware use is documented. EPSS is high at roughly 0.56 (99th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Apply the vendor fix or upgrade to a non-vulnerable SolarWinds TFTP Server release if one is available; the record does not name a fixed version.
- If no patch is available, restrict TFTP access to trusted hosts with firewall or ACL rules and disable the service where it is not needed.
- Place the TFTP service behind network segmentation so a DoS does not affect other management or provisioning systems.
- Monitor the service for restart or connection-refusal events and treat repeated occurrences as an attack indicator.
Detection
- Alert on TFTP service process crashes, restarts, or a sudden stop in accepting new connections.
- Monitor for repeated or malformed TFTP read (RRQ) requests from a single source or unusual sources.
- Baseline normal TFTP client sources and flag connections from hosts that do not normally use the service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2115 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2115), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.