Serv U

Vendor:

First CVE: May 16, 2018 · Active for 8 years

55
Total CVEs
More Total CVEs than 98% of tracked products
6.9
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
7.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Serv U over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2018
8 years ago
Most Recent CVE
Jul 21, 2026
6 days ago

CVE Severity & Scoring

Serv U55 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local1 (1.8%)
Network54 (98.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low55 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None45 (81.8%)
Unknown0 (0.0%)
Required10 (18.2%)
Privileges Required
Low13 (23.6%)
High27 (49.1%)
None15 (27.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
Jun 6, 20247.598YESYES
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may b
Jul 14, 202110.095YESNO
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provi
Jun 4, 20267.581YESNO
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional valida
Jan 10, 20225.357YESNO
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. Th
Jul 21, 20269.140NONO
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows dep
Jul 21, 20269.140NONO
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requir
Jul 21, 20269.140NONO
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been
Apr 25, 20227.540NOYES
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute cod
Jul 21, 20269.139NONO
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execut
Jul 21, 20269.139NONO

Exploit Exposure

Signals from CVEs in this product scope (55 CVEs).

CISA KEV
4 CVEs
7.3% of CVEs· 98th percentile
Metasploit
1 CVE
1.8% of CVEs· 97th percentile
Nuclei
2 CVEs
3.6% of CVEs· 97th percentile
ExploitDB
1 CVE
1.8% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (55 CVEs).

Media Mentions

Signals from CVEs in this product scope (55 CVEs).

Top CNAs Publishing CVEs For Serv U

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
15.5.417.58.3%10
15.4.226.666.6%11
15.4.036.10.9%00
15.3.115.40.7%00
15.3.015.40.7%00
15.317.514.7%01
15.2.516.81.2%00
15.2.416.81.2%00
15.2.3110.091.2%10
15.2.217.10.5%00