Junglewise Threat Intelligence

CVE-2021-35247: SolarWinds Serv-U Improper Input Validation Vulnerability

CVE-2021-35247 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2022-01-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

The SolarWinds Serv-U web login screen failed to sufficiently sanitize characters used in LDAP authentication. This improper input validation allowed attackers to build and send unsanitized queries, though the vendor noted that many LDAP servers ignored the improper characters.

Affected products

  • SolarWinds Serv-U <= 15.2.5

Timeline

  • 2022-01-18: disclosed: Initial disclosure by SolarWinds regarding LDAP input validation improvements.
  • 2022-01-21: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-01-21: advisory: NVD publication date.
  • 2022-01-21: exploited: Reported as exploited in the wild.

Related threats