First published: Tue Aug 31 2021(Updated: )
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U | <15.2.4 |
SolarWinds recommends customers upgrade to the latest version of the product as soon as possible. Upgrading the software will remediate this vulnerability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35223 is a vulnerability in the Serv-U File Server that allows for remote code execution.
CVE-2021-35223 has a severity score of 8.8 (high).
The Serv-U File Server up to version 15.2.4 is affected by CVE-2021-35223.
CVE-2021-35223 can be exploited by supplying parameters that can execute a remote code on the server.
To fix CVE-2021-35223, upgrade Serv-U File Server to version 15.2.4 or higher.