PT-2022-10453 · Solarwinds · Serv-U
Published
2022-04-25
·
Updated
2024-09-17
·
CVE-2021-35250
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Serv-U versions 15.3.0.X through 15.3.0.X before Hotfix 1
Serv-U version 15.3
Description
A researcher reported a Directory Transversal issue in Serv-U. This may allow access to files relating to the Serv-U installation and server files. The issue allows a remote user to perform a Directory Traversal attack and read arbitrary files in systems with Serv-U version 15.3 installed. The attack can be performed by sending a specially crafted HTTP request. The reading of files is only possible on the C: disk, and the attacker can only obtain information about the file server if they know the path to the files.
Recommendations
For Serv-U versions 15.3.0.X through 15.3.0.X before Hotfix 1, apply Hotfix 1 to resolve the issue.
For Serv-U version 15.3, apply Hotfix 1 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive files and directories on the C: disk to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serv-U