Home / Vulnerabilities / CVE-2021-35247
MEDIUM SEVERITY
CVE-2021-35247 SolarWinds · Serv-U

SolarWinds Serv-U Improper Input Validation Vulnerability

Technical Severity

CVSS v3.1 Metrics

MEDIUM
4.3 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitation Likelihood

EPSS Prediction

2.92 %
Predictive Probability
Percentile Rank
86.1 th

Documented as more likely to be exploited than 86.1% of known CVEs.

Detection Date

Jan 21, 2022

Remediation Due

Feb 04, 2022

CISA Catalog Active

Threat Analysis

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

Remediation Directive

Apply updates per vendor instructions.

External Intelligence