Описание
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of ‘user string variables,” allowing remote code execution.
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of ‘user string variables,” allowing remote code execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-35223
- https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-2-4_release_notes.htm
- https://support.solarwinds.com/SuccessCenter/s/article/Execute-Command-Function-Allows-Remote-Code-Execution-RCE-Vulnerability-CVE-2021-35223?language=en_US
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35223
EPSS
Процентиль: 90%
0.05282
Низкий
CVE ID
Связанные уязвимости
CVSS3: 8.5
nvd
больше 4 лет назад
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
EPSS
Процентиль: 90%
0.05282
Низкий