VYPR

Serv-U

by Serv U

CVEs (12)

  • CVE-2025-40549CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium…

  • CVE-2025-40548CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services…

  • CVE-2025-40547CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because…

  • CVE-2021-35250HigApr 25, 2022
    risk 0.50cvss 7.5epss 0.13

    A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.

  • CVE-2023-35179HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 

  • CVE-2022-38106MedDec 16, 2022
    risk 0.35cvss 5.4epss 0.01

    This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

  • CVE-2023-40053MedDec 6, 2023
    risk 0.33cvss 5.0epss 0.01

    A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.

  • CVE-2009-0967Mar 19, 2009
    risk 0.04cvss epss 0.07

    The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument.

  • CVE-2008-4500Oct 9, 2008
    risk 0.04cvss epss 0.10

    Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".

  • CVE-2004-1675Sep 11, 2004
    risk 0.04cvss epss 0.12

    Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.

  • CVE-2009-4815Apr 27, 2010
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • CVE-2002-2393Dec 31, 2002
    risk 0.00cvss epss 0.03

    Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.