← Vulnerability feed

Vulnerability record · CVE-2021-35247 · published 10 January 2022

CVE-2021-35247: SolarWinds Serv-U web login LDAP input validation flaw

Solarwinds · Serv U

The Serv-U web login screen passed characters to LDAP authentication without sufficient sanitization. SolarWinds updated the input mechanism to add validation and sanitization, and states no downstream impact was detected because LDAP servers ignored the improper characters. The flaw is an improper input validation issue in the authentication path.

5.3 CVSS 3.1 Medium CISA KEV since 21 Jan 2022 EPSS 3.5% · top 11.4% CWE-20 · Improper input validation
5.3CVSS 3.1 base score, v2 5.0
3.5%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityThe CVSS score is 5.3 with only low integrity impact, but the CVE is in CISA KEV, so it warrants prompt patching despite limited technical severity.

What it is

The Serv-U web login screen passed characters to LDAP authentication without sufficient sanitization. SolarWinds updated the input mechanism to add validation and sanitization, and states no downstream impact was detected because LDAP servers ignored the improper characters. The flaw is an improper input validation issue in the authentication path.

Impact

The CVSS vector shows only low integrity impact with no confidentiality or availability impact, so the practical attacker gain is limited to manipulating input handling rather than reading data or causing denial of service. SolarWinds reports no observed downstream effect.

Attack surface

Reachable over the network through the Serv-U web login screen that forwards credentials to LDAP; the vector indicates no privileges and no user interaction are required. The description does not specify which Serv-U versions are affected.

Exploitation

CVE-2021-35247 is listed in CISA KEV with a 2022-01-21 addition date, indicating known exploitation, while EPSS is low at roughly 3.5 percent for 30 days. No ransomware campaign use is recorded and no public exploit reference is included in the record.

What to do

  • Update Serv-U to the latest version per the vendor release notes, which document the added input validation and sanitization.
  • If immediate patching is not possible, restrict network access to the Serv-U web login interface to trusted management networks.
  • Review LDAP authentication logs for malformed or unexpected characters submitted through the Serv-U login screen.
  • Confirm LDAP server-side input handling and logging so improper characters are rejected and recorded.
  • Track the CISA KEV due date and verify remediation status for all exposed Serv-U instances.

Detection

  • Monitor Serv-U web login requests for unusual or non-conforming characters in username or credential fields.
  • Alert on repeated authentication attempts containing special characters or encoding patterns against the Serv-U login endpoint.
  • Correlate Serv-U authentication events with LDAP server logs for rejected or malformed bind attempts.
  • Inventory internet-facing Serv-U deployments and verify version levels against the fixed release.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-35247 to the Known Exploited Vulnerabilities catalog on 21 January 2022 as "SolarWinds Serv-U Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 4 February 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35247 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-35211SolarWinds Serv-U out-of-bounds write enables remote code executionSolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 contain an out-of-bounds write (CWE-787) that Microsoft d…KEVEPSS 91%analysed7.5CVE-2026-28318SolarWinds Serv-U unauthenticated POST request denial of serviceSolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authenticat…KEVEPSS 1.9%analysed7.5CVE-2024-28995SolarWinds Serv-U path traversal allows arbitrary file readSolarWinds Serv-U contains a path traversal flaw (CWE-22) that lets an unauthenticated remote attacker read sensitive files from the host. The vulner…KEVEPSS 100%analysed9.8CVE-2020-35481Solarwinds serv-u vulnerabilitySolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.EPSS 1.3%9.1CVE-2026-28317Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …EPSS 0.50%9.1CVE-2026-28321Solarwinds serv-u improper access control vulnerabilitySolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to esca…EPSS 0.58%9.1CVE-2026-28312Solarwinds serv-u improper authorization vulnerabilitySolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe…EPSS 0.58%9.1CVE-2026-28313Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2021-35247), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.