Vulnerability record · CVE-2021-35247 · published 10 January 2022
CVE-2021-35247: SolarWinds Serv-U web login LDAP input validation flaw
Solarwinds · Serv U
The Serv-U web login screen passed characters to LDAP authentication without sufficient sanitization. SolarWinds updated the input mechanism to add validation and sanitization, and states no downstream impact was detected because LDAP servers ignored the improper characters. The flaw is an improper input validation issue in the authentication path.
Description
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers ignored improper characters. To insure proper input validation is completed in all environments. SolarWinds recommends scheduling an update to the latest version of Serv-U.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Automated analysis
medium priorityThe CVSS score is 5.3 with only low integrity impact, but the CVE is in CISA KEV, so it warrants prompt patching despite limited technical severity.
What it is
The Serv-U web login screen passed characters to LDAP authentication without sufficient sanitization. SolarWinds updated the input mechanism to add validation and sanitization, and states no downstream impact was detected because LDAP servers ignored the improper characters. The flaw is an improper input validation issue in the authentication path.
Impact
The CVSS vector shows only low integrity impact with no confidentiality or availability impact, so the practical attacker gain is limited to manipulating input handling rather than reading data or causing denial of service. SolarWinds reports no observed downstream effect.
Attack surface
Reachable over the network through the Serv-U web login screen that forwards credentials to LDAP; the vector indicates no privileges and no user interaction are required. The description does not specify which Serv-U versions are affected.
Exploitation
CVE-2021-35247 is listed in CISA KEV with a 2022-01-21 addition date, indicating known exploitation, while EPSS is low at roughly 3.5 percent for 30 days. No ransomware campaign use is recorded and no public exploit reference is included in the record.
What to do
- Update Serv-U to the latest version per the vendor release notes, which document the added input validation and sanitization.
- If immediate patching is not possible, restrict network access to the Serv-U web login interface to trusted management networks.
- Review LDAP authentication logs for malformed or unexpected characters submitted through the Serv-U login screen.
- Confirm LDAP server-side input handling and logging so improper characters are rejected and recorded.
- Track the CISA KEV due date and verify remediation status for all exposed Serv-U instances.
Detection
- Monitor Serv-U web login requests for unusual or non-conforming characters in username or credential fields.
- Alert on repeated authentication attempts containing special characters or encoding patterns against the Serv-U login endpoint.
- Correlate Serv-U authentication events with LDAP server logs for rejected or malformed bind attempts.
- Inventory internet-facing Serv-U deployments and verify version levels against the fixed release.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-35247 to the Known Exploited Vulnerabilities catalog on 21 January 2022 as "SolarWinds Serv-U Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 4 February 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3_release_notes.htm | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247 | Broken LinkVendor Advisory |
| https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-3_release_notes.htm | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247 | Broken LinkVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35247 | US Government Resource |
Track CVE-2021-35247 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35247), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.