CVE-2021-35247 is a medium-severity vulnerability affecting SolarWinds Serv-U, where insufficient input sanitization on the web login screen for LDAP authentication could allow improper characters. While LDAP servers typically ignored these characters, SolarWinds has released an update to perform additional validation. The vulnerability has a CVSS score of 5.3 (MEDIUM) with a network attack vector and low attack complexity, potentially leading to limited integrity impact. This CVE is actively exploited, listed in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.3CPE matchmatch criteria | cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.