First published: Thu Dec 02 2021(Updated: )
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Serv-U FTP Server | <15.2.4 | |
SolarWinds Serv-U FTP Server | =15.2.4-hotfix1 | |
SolarWinds Serv-U FTP Server | =15.2.5 | |
Microsoft Windows |
All customers should upgrade to the latest version of Serv-U 15.2.5 as soon as the update is available.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35245 is considered a high-severity vulnerability due to its potential to allow unauthorized file access and modifications by users with admin rights.
To fix CVE-2021-35245, ensure you apply the latest patches provided by SolarWinds for Serv-U, specifically versions newer than 15.2.4 and 15.2.5.
CVE-2021-35245 affects users of SolarWinds Serv-U versions up to 15.2.4 and 15.2.4-hotfix1, and Serv-U version 15.2.5.
CVE-2021-35245 allows users with admin rights to manipulate files on the Serv-U host machine, posing data integrity and confidentiality risks.
If you are using a vulnerable version of SolarWinds Serv-U, your installation is at risk for CVE-2021-35245.