Serv U Ftp Server

Vendor:

First CVE: Mar 21, 2019 · Active for 7 years

11
Total CVEs
More Total CVEs than 90% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Serv U Ftp Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2019
7 years ago
Most Recent CVE
May 5, 2021
1,910 days ago

CVE Severity & Scoring

Serv U Ftp Server11 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (63.6%)
Unknown0 (0.0%)
Required4 (36.4%)
Privileges Required
Low5 (45.5%)
High3 (27.3%)
None3 (27.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
Jun 17, 20198.881NOYES
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
Jul 5, 20209.835NONO
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
Mar 21, 20197.227NONO
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execu
Jun 7, 20197.825NONO
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
Jul 5, 20209.824NONO
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
Jul 5, 20209.824NONO
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
Dec 16, 20195.421NONO
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
Mar 21, 20194.820NONO
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
Dec 18, 20195.419NONO
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
May 5, 20214.818NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Serv U Ftp Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
15.1.735.84.0%00
15.1.6.2526.33.0%00
15.1.617.28.1%00
15.114.81.2%00