Serv U File Server
by SolarWinds
CVEs (38)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15543 | Cri | 0.64 | 9.8 | 0.02 | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path. | ||
| CVE-2020-15542 | Cri | 0.64 | 9.8 | 0.02 | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command. | ||
| CVE-2020-15541 | Cri | 0.64 | 9.8 | 0.07 | Jul 5, 2020 | SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution. | ||
| CVE-2021-35245 | Hig | 0.55 | 8.4 | 0.01 | Dec 6, 2021 | When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. | ||
| CVE-2021-35223 | Hig | 0.55 | 8.5 | 0.03 | Aug 31, 2021 | The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution. | ||
| CVE-2021-35242 | Hig | 0.54 | 8.3 | 0.01 | Dec 6, 2021 | Serv-U server responds with valid CSRFToken when the request contains only Session. | ||
| CVE-2018-19999 | Hig | 0.51 | 7.8 | 0.01 | Jun 7, 2019 | The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit… | ||
| CVE-2021-35252 | Hig | 0.49 | 7.5 | 0.01 | Dec 16, 2022 | Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext. | ||
| CVE-2020-15576 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2020 | SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response. | ||
| CVE-2020-15574 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2020 | SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893. | ||
| CVE-2018-15906 | Hig | 0.47 | 7.2 | 0.08 | Mar 21, 2019 | SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file. | ||
| CVE-2019-13181 | Med | 0.43 | 6.5 | 0.03 | Dec 16, 2019 | A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. | ||
| CVE-2021-25179 | Med | 0.40 | 6.1 | 0.01 | May 5, 2021 | SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header. | ||
| CVE-2020-15575 | Med | 0.40 | 6.1 | 0.02 | Jul 7, 2020 | SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. | ||
| CVE-2020-15573 | Med | 0.40 | 6.1 | 0.02 | Jul 7, 2020 | SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. | ||
| CVE-2019-13182 | Med | 0.36 | 5.4 | 0.06 | Dec 16, 2019 | A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. | ||
| CVE-2022-38106 | Med | 0.35 | 5.4 | 0.01 | Dec 16, 2022 | This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function. | ||
| CVE-2019-19829 | Med | 0.35 | 5.4 | 0.02 | Dec 18, 2019 | A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182. | ||
| CVE-2018-19934 | Med | 0.32 | 4.8 | 0.05 | Mar 21, 2019 | SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter. | ||
| CVE-2009-4006 | 0.10 | — | 0.83 | Nov 20, 2009 | Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string. |
- risk 0.64cvss 9.8epss 0.02
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
- risk 0.64cvss 9.8epss 0.02
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
- risk 0.64cvss 9.8epss 0.07
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
- risk 0.55cvss 8.4epss 0.01
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
- risk 0.55cvss 8.5epss 0.03
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
- risk 0.54cvss 8.3epss 0.01
Serv-U server responds with valid CSRFToken when the request contains only Session.
- risk 0.51cvss 7.8epss 0.01
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit…
- risk 0.49cvss 7.5epss 0.01
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
- risk 0.49cvss 7.5epss 0.02
SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.
- risk 0.49cvss 7.5epss 0.02
SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.
- risk 0.47cvss 7.2epss 0.08
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
- risk 0.43cvss 6.5epss 0.03
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
- risk 0.40cvss 6.1epss 0.01
SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.
- risk 0.40cvss 6.1epss 0.02
SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.
- risk 0.40cvss 6.1epss 0.02
SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.
- risk 0.36cvss 5.4epss 0.06
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
- risk 0.35cvss 5.4epss 0.01
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
- risk 0.35cvss 5.4epss 0.02
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
- risk 0.32cvss 4.8epss 0.05
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
- CVE-2009-4006Nov 20, 2009risk 0.10cvss —epss 0.83
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.
Page 1 of 2