Description
The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/7925
Exploit, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/279763
Exploit vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1002882
Scores
EPSS
0.0366
EPSS Percentile
88.0%
Details
CWE
CWE-310
Status
published
Products (2)
solarwinds/serv-u_file_server
3.0.0.16
solarwinds/serv-u_file_server
3.0.0.17
Published
Nov 19, 2001
Tracked Since
Feb 18, 2026