Serv-U FTP Server < 15.3 Improper Input Validation

medium Nessus Plugin ID 156886


The remote FTP server is affected by an Improper Input Validation vulnerability.


According to its banner, the installed version of Serv-U is a version prior to 15.3. It is, therefore, affected by an improper input validation vulnerability. The Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized.

SolarWinds has updated the input mechanism to perform additional validation and sanitization.

Please Note: No downstream effect has been detected as the LDAP servers ignored improper characters.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.


Upgrade to ServU-FTP 15.3 or later.

See Also

Plugin Details

Severity: Medium

ID: 156886

File Name: servu_15_3.nasl

Version: 1.8

Type: remote

Family: FTP

Published: 1/20/2022

Updated: 4/25/2023

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information


Risk Factor: Low

Score: 2.9


Risk Factor: Medium

Base Score: 5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2021-35247


Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:solarwinds:serv-u_file_server, cpe:/a:solarwinds:serv-u

Required KB Items: installed_sw/Serv-U

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/18/2022

Vulnerability Publication Date: 1/10/2022

CISA Known Exploited Vulnerability Due Dates: 2/4/2022

Reference Information

CVE: CVE-2021-35247

IAVA: 2022-A-0047-S