← Vulnerability feed

Vulnerability record · CVE-2008-4500 · published 9 October 2008

CVE-2008-4500: Solarwinds serv-u file server improper input validation vulnerability

Solarwinds · Serv U File Server

Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".

4.0 CVSS 2.0 Medium EPSS 10% · top 4.5% CWE-20 · Improper input validation
4.0CVSS 2.0 base score
10%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".

AV:N/AC:L/Au:S/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4500 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4006Serv-U FTP Server TEA Decoding Stack Buffer OverflowRhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigge…EPSS 83%analysed10.0CVE-2004-2532Solarwinds serv-u file server vulnerabilityServ-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands …EPSS 15%10.0CVE-2004-0330Serv-U FTP MDTM time zone buffer overflow allows remote code executionServ-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FT…EPSS 85%analysed9.0CVE-2011-4800Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list …EPSS 7.3%9.0CVE-2008-4501Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite …EPSS 11%8.5CVE-2004-2111Serv-U FTP Server site chmod stack buffer overflowServ-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can iss…EPSS 87%analysed7.8CVE-2009-1031Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create ar…EPSS 11%7.5CVE-2001-1463Solarwinds serv-u file server vulnerabilityThe remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2008-4500), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.