Vulnerability Analysis
Improper Input Validation Vulnerability in Serv-U
CVE-2021-35247
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
CISA KEV
CVSS Base Score
4.3
MEDIUM
Exploitability:2.9
Impact Score:1.5
Temporal Score:-
EPSS:3.36%
Threat Intelligence Signals
CISA KEV
YES
KEV Date Added
2022-01-21
Ransomware Use
Unknown
KEV Due Date
2022-02-04
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
3.359%
EPSS Percentile
87.2th pct
GHSA ID
GitHub Severity
CRITICAL
SSVC Exploitation
—
SSVC Automatable
—
Vulnerability Class
—
Identity & Timeline
| Status | - |
| Assigning Authority | - |
| CVSS Version / Source | - |
| Reserved | - |
| Published | - |
| Patch Date (date_public) | - |
| Exploit DB Date | - |
| First GitHub PoC Date | - |
| Last Updated | - |
| Time to Patch (Days to fix) | - |
| Exploit Release Gap | - |
| PoC Release Gap | - |
| Exploit DB References | None identified |
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| No affected products specified. | ||
Social Buzz