Threat Encyclopedia

SolarWinds.Serv-U.FTP.Unauthorized.User.Creation

Description

This indicates an attack attempt against an Authentication Bypass vulnerability in SolarWinds Serv-U FTP software.
The vulnerability is due to insufficient sanitizing of user supplied inputs. A remote attacker may be able to exploit this to create arbitrary users with elevated privileges (administrator) on the server.

Affected Products

All Serv-U versions prior to 15.2.3 HF2

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211

CVE References

CVE-2021-35211