CVE-2009-3655: Medium severity solarwinds serv-u ftp server vulnerability
Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3655?
CVE-2009-3655 has a severity rating of medium due to its potential to cause a denial of service.
How do I fix CVE-2009-3655?
To fix CVE-2009-3655, upgrade to a version of Solarwinds Serv-U File Server that is not vulnerable, such as any version beyond 8.2.0.3.
What types of attacks are possible with CVE-2009-3655?
CVE-2009-3655 allows remote attackers to exploit the vulnerability to crash the server using the "SITE SET TRANSFERPROGRESS ON" FTP command.
Which versions of Solarwinds Serv-U File Server are affected by CVE-2009-3655?
Versions 7.0.0.1 through 8.2.0.3 of Solarwinds Serv-U File Server are affected by CVE-2009-3655.
Is there a workaround for CVE-2009-3655?
There is no documented workaround for CVE-2009-3655, hence upgrading to a patched version is recommended.