Record summary

CVE-2021-35250 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 24, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List, VulnCheck15.3 only to < 15.3 Hotfix 1affected

Proofs of concept

1

Repository PoCs

GitHubrissor41/SolarWinds-CVE-2021-35250Repository PoCby rissor41Stars: 9Not analyzed1 file

2.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHSolarWinds Serv-U 15.3 - Directory TraversalCVSS 7.5

SolarWinds Serv-U 15.3 is susceptible to local file inclusion, which may allow an attacker access to installation and server files and also make it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further attacks.

Remediation

Resolved in Serv-U 15.3 Hotfix 1.

WeaknessesCWE-22
Authorsjohnk3r, pdteam
Template tagscve2021cvesolarwindstraversalvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:solarwinds:serv-u:15.3:-:*:*:*:*:*:*
Shodan: product:"Rhinosoft Serv-U httpd"
Shodan: product:"rhinosoft serv-u httpd"

Source: ProjectDiscovery

References

3