CVE-2021-35247
SolarWinds Serv-U Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 4 February 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 3.45% probability · 88th percentile
- CISA KEV
- Listed 21 January 2022 · due 4 February 2022
- Weakness
- CWE-20
- Affected
- solarwinds/serv-u
- Source
- psirt@solarwinds.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-35247
References
- https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3_release_notes.htmRelease Notes, Vendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247Broken Link, Vendor Advisory
- https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3_release_notes.htmRelease Notes, Vendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247Broken Link, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35247US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.