Serv U File Server
Vendor:
First CVE: Feb 16, 2001 · Active for 25 years
20
Total CVEs
More Total CVEs than 95% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Serv U File Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2001
25 years ago
Most Recent CVE
May 5, 2021
1,910 days ago
CVE Severity & Scoring
Serv U File Server20 CVEs
60%
40%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (5.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None0 (0.0%)
Unknown19 (95.0%)
Required1 (5.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (5.0%)
Unknown19 (95.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4006HIGH Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbi | Nov 20, 2009 | 10.0 | 86 | NO | YES |
CVE-2004-2111HIGH Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename. | Dec 31, 2004 | 8.5 | 85 | NO | YES |
CVE-2004-0330HIGH Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command. | Nov 23, 2004 | 10.0 | 85 | NO | YES |
CVE-2004-2532HIGH Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server usi | Dec 31, 2004 | 10.0 | 44 | NO | YES |
CVE-2008-4501HIGH Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a | Oct 9, 2008 | 9.0 | 41 | NO | YES |
CVE-2011-4800HIGH Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list and create arbitrary directorie | Dec 14, 2011 | 9.0 | 39 | NO | YES |
CVE-2009-1031HIGH Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. ( | Mar 20, 2009 | 7.8 | 36 | NO | YES |
CVE-2004-1675MEDIUM Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as | Sep 11, 2004 | 5.0 | 33 | NO | YES |
CVE-2001-0054MEDIUM Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD | Feb 16, 2001 | 5.0 | 33 | NO | YES |
CVE-2004-1992MEDIUM Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read. | Apr 20, 2004 | 5.0 | 30 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
15.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
60.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Serv U File Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4.0.2 | 1 | 9.0 | 8.4% | 0 | 1 |
| 9.4.0.0 | 1 | 9.0 | 8.4% | 0 | 1 |
| 9.3.0.1 | 1 | 9.0 | 8.4% | 0 | 1 |
| 9.2.0.1 | 1 | 9.0 | 8.4% | 0 | 1 |
| 9.1.0.2 | 2 | 6.5 | 5.6% | 0 | 1 |
| 9.1.0.0 | 3 | 7.7 | 31.4% | 0 | 2 |
| 9.0.0.5 | 3 | 7.7 | 31.4% | 0 | 2 |
| 9.0.0.3 | 3 | 7.7 | 31.4% | 0 | 2 |
| 9.0.0.1 | 3 | 7.7 | 31.4% | 0 | 2 |
| 8.2.0.3 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.2.0.1 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.2.0.0 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.1.0.3 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.1.0.1 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.0.0.7 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.0.0.5 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.0.0.4 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.0.0.2 | 4 | 7.0 | 24.6% | 0 | 2 |
| 8.0.0.1 | 4 | 7.0 | 24.6% | 0 | 2 |
| 7.4.0.1 | 6 | 6.6 | 19.4% | 0 | 4 |