CVE-2021-35247
בינונית 5.3 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- SolarWinds Serv-U Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-20
מוצרים מושפעים
solarwinds: serv-u
קישורים
- https://documentation.solarwinds.com/en/success_center/servu/content/release_n… Release NotesVendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247 Broken LinkVendor Advisory
- https://documentation.solarwinds.com/en/success_center/servu/content/release_n… Release NotesVendor Advisory
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247 Broken LinkVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource