CVE-2004-2532: Critical severity SolarWinds Serv-u File Server vulnerability
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2532?
CVE-2004-2532 is considered a high severity vulnerability due to the potential for arbitrary command execution by unauthorized users.
How do I fix CVE-2004-2532?
To fix CVE-2004-2532, it is recommended to update the Serv-U FTP server to a version that is not affected, specifically versions after 5.1.0.0.
What software is affected by CVE-2004-2532?
CVE-2004-2532 affects several versions of Solarwinds Serv-U File Server including versions up to 5.0.0.11.
Can local users exploit CVE-2004-2532?
Yes, local users can exploit CVE-2004-2532 by utilizing the default administrator account to execute arbitrary commands.
Is there a default account for CVE-2004-2532?
Yes, CVE-2004-2532 includes a default account and password for local administration on the affected Serv-U FTP server versions.