CVE-2021-35223: Execute Command Function Allows Remote Code Execution (RCE)Vulnerability
Published Aug 31, 2021
·Updated
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
Affected Software
1 affected component
SolarWinds Serv-U<15.2.4
Remediation
Information
SolarWinds recommends customers upgrade to the latest version of the product as soon as possible. Upgrading the software will remediate this vulnerability.
Event History
Aug 31, 2021
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-35223?
CVE-2021-35223 is a vulnerability in the Serv-U File Server that allows for remote code execution.
2
How severe is CVE-2021-35223?
CVE-2021-35223 has a severity score of 8.8 (high).
3
Which software is affected by CVE-2021-35223?
The Serv-U File Server up to version 15.2.4 is affected by CVE-2021-35223.
4
How can CVE-2021-35223 be exploited?
CVE-2021-35223 can be exploited by supplying parameters that can execute a remote code on the server.
5
How can I fix CVE-2021-35223?
To fix CVE-2021-35223, upgrade Serv-U File Server to version 15.2.4 or higher.