QID 375701
Date Published: 2021-07-14
QID 375701: SolarWinds Serv-U FTP Remote Code Execution Vulnerability (CVE-2021-35211)
SolarWinds Serv-U FTP Server is a file transfer software.
SolarWinds Serv-U Managed File Transfer Server and Serv-U Secured FTP before 15.2.3 HF2 is affected by a Memory Escape Vulnerability.
An attacker can use this vulnerability to run arbitrary code with privileges. The attacker could then install programs, view, change, or delete data; or run programs on the affected system.
Affected Versions:
Serv-U 15.2.3 HF1 and all prior Serv-U versions
QID Detection Logic (authenticated):
This QID checks for the vulnerable version of SolarWinds Serv-U from file Serv-U.exe
QID Detection Logic (unauthenticated):
This QID checks for the vulnerable version of SolarWinds Serv-U from the ftp banner.
Successful exploitation of the vulnerability will allow remote code execution.
- CVE-2021-35211 -
www.solarwinds.com/trust-center/security-advisories/cve-2021-35211
CVEs related to QID 375701
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SolarWinds Serv-U FTP Server |
|