ZeroHour

CVE-2021-35247

KEVmoderate

Actively Exploited Input Validation Flaw in SolarWinds Serv-U LDAP Login

CISA: SolarWinds Serv-U Improper Input Validation Vulnerability

CVSS 3.1
5.3 medium
EPSS
3%p88
Published
()
KEV added
AI analysis

CVE-2021-35247 is an improper input validation flaw (CWE-20) in the SolarWinds Serv-U web login screen's LDAP authentication path, where submitted characters are not sufficiently sanitized before being passed to the LDAP server. It is triggered remotely over the network with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), by sending crafted, non-sanitized characters through the login-to-LDAP flow; SolarWinds notes that LDAP servers ignored the improper characters and no downstream effect was detected, and the 5.3 (medium) CVSS score reflects a low integrity impact with no confidentiality or availability impact. An attacker gains the ability to feed unsanitized input into the LDAP authentication process; no confirmed code execution or full compromise is documented for this specific bug, but it is nevertheless on CISA's Known Exploited Vulnerabilities catalog. Affected organizations are those running SolarWinds Serv-U whose web login screen uses LDAP authentication. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2022-01-21, Microsoft warned that threat actors attempted to exploit the Serv-U bug in real-world attacks, and reporting on this flaw surfaced alongside the Log4j (Log4Shell) attack wave targeting SolarWinds products.

What to do: Schedule an upgrade to the latest SolarWinds Serv-U release, which adds the required input validation and sanitization to the LDAP login path; this is the CISA KEV required action, so KEV deadlines apply. Until patched, restrict access to the Serv-U web login from untrusted networks and review LDAP/authentication logs for suspicious or malformed login input. While updating, also confirm Serv-U is patched for the related critical Serv-U 15.5 root code execution flaws and any Log4j exposure covered in the same reporting cycle.

Affected
SolarWinds Serv-U
Estimated exposure
moderate≈ several thousand internet-exposed Serv-U servers (estimate; no scan counts in source data) — Serv-U is a niche on-premises FTP/SFTP/MFT server typically deployed as a single internet-facing host per organization rather than mass-market software, so the plausible affected base is on the order of thousands of exposed servers, not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

CISA Known Exploited Vulnerability
Affected
SolarWinds Serv-U
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
solarwinds
Products
serv-u
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news