CVE-2021-35247
Summary
| CVE | CVE-2021-35247 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-10 14:10:00 UTC |
| Updated | 2022-02-10 15:08:00 UTC |
| Description | Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U. |
Risk And Classification
EPSS: 0.053450000 probability, percentile 0.900320000 (date 2026-04-02)
CISA KEV: Listed on 2022-01-21; due 2022-02-04; ransomware use Unknown
Problem Types: CWE-20
CISA Known Exploited Vulnerability
| Vendor | SolarWinds |
|---|---|
| Product | Serv-U |
| Name | SolarWinds Serv-U Improper Input Validation Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2021-35247 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | Serv-u | All | All | All | All |
| Application | Solarwinds | Serv-u | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Serv-U File Server 15.3 Release Notes | MISC | documentation.solarwinds.com | |
| Page Not Found. | MISC | www.solarwinds.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: SolarWinds would like to thank Jonathan Bar Or of Microsoft (@yo_yo_yo_jbo) for reporting this vulnerability
Legacy QID Mappings
- 376260 SolarWinds Serv-U Improper Input Validation Vulnerability