Known Vulnerabilities for Serv-u by Solarwinds
Listed below are 10 of the newest known vulnerabilities associated with "Serv-u" by "Solarwinds".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-40060 json | A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-... | 7.2 - HIGH | 2023-09-07 | 2023-09-14 |
| CVE-2023-35179 json | A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor... | 7.2 - HIGH | 2023-08-11 | 2023-09-14 |
| CVE-2023-23841 json | SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. ... | 7.5 - HIGH | 2023-06-15 | 2023-11-07 |
| CVE-2022-38106 json | This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory crea... | 5.4 - MEDIUM | 2022-12-16 | 2023-08-03 |
| CVE-2021-35252 json | Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted val... | 7.5 - HIGH | 2022-12-16 | 2023-08-03 |
| CVE-2021-35250 json | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Se... | 7.5 - HIGH | 2022-04-25 | 2023-08-03 |
| CVE-2021-35249 json | This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of ... | 4.3 - MEDIUM | 2022-05-17 | 2022-10-27 |
| CVE-2021-35247 json | Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has u... | 5.3 - MEDIUM | 2022-01-10 | 2022-02-10 |
| CVE-2021-35245 json | When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the... | 6.8 - MEDIUM | 2021-12-06 | 2022-10-27 |
| CVE-2021-35242 json | Serv-U server responds with valid CSRFToken when the request contains only Session. | 8.8 - HIGH | 2021-12-06 | 2021-12-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | Serv-u | 15.2.1 | |||
| Application | Solarwinds | Serv-u | 15.1.6 |