| VID |
16156 |
| Severity |
30 |
| Port |
21 |
| Protocol |
TCP |
| Class |
FTP |
| Detailed Description |
According to its banner, the installed version of Serv-U is a version prior to 15.3. It is, therefore, affected by an improper input validation vulnerability. The Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized.
SolarWinds has updated the input mechanism to perform additional validation and sanitization.
Please Note: No downstream effect has been detected as the LDAP servers ignored improper characters.
* Note: This check solely relied on the version number of the remote FTP server to assess this vulnerability, so this might be a false positive.
* References: https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247
* Platforms Affected: Rhino Software, Inc., Serv-U FTP Server 15.3 prior Microsoft Windows Any version |
| Recommendation |
Upgrade to latest version of Serv-U (15.3 or later), available from Serv-U Web site at http://www.serv-u.com/ |
| Related URL |
CVE-2021-35247 (CVE) |
| Related URL |
(SecurityFocus) |
| Related URL |
(ISS) |
|