CVE Feed

    Dashboard / CVE / CVE-2021-25276

    CVE-2021-25276

    In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a user with a C:\ home directory, then the attacker obtains access to read or replace arbitrary files with LocalSystem privileges.

    Published:Feb 3, 2021
    Last Modified:Nov 21, 2024
    EPS:Feb 3, 2021
    EPSS Score:0.00247
    CVSS Score:7.1

    Affected Products

    Vendor
    Solarwinds
    Product
    Serv-u

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High