← Back to CVE List
Vulnerability Analysis
Improper Input Validation Vulnerability in Serv-U

CVE-2021-35247

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

CISA KEV
CVSS Base Score
4.3
MEDIUM
Exploitability:2.9
Impact Score:1.5
Temporal Score:-
EPSS:3.36%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2022-01-21
Ransomware Use
Unknown
KEV Due Date
2022-02-04
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
3.359%
EPSS Percentile
87.2th pct
GitHub Severity
CRITICAL
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD