Execute Command Function Allows Remote Code Execution (RCE)Vulnerability
Vulnerability Description
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-35223
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- SolarWinds would like to thank Exodus Intelligence (exodusintel.com) for reporting on the issue in a responsible manner
References
- https://support.solarwinds.com/SuccessCenter/s/article/Execute-Command-Function-Allows-Remote-Code-Execution-RCE-Vulnerability-CVE-2021-35223?language=en_US
- https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-2-4_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35223
More from SolarWinds
View All →Affected Vendor
SolarWinds
View all reports →