Directory Traversal Vulnerability in SolarWinds Serv-U FTP Software
CVE-2021-25276
7.1HIGH
Summary
A vulnerability in SolarWinds Serv-U FTP software prior to version 15.2.2 Hotfix 1 allows unprivileged Windows users to gain unauthorized access to a directory containing user profile files, which include sensitive password hashes. By copying an existing valid profile file into this world-readable and writable directory, potential attackers can create new FTP users or replace existing files, effectively gaining LocalSystem privileges and compromising system security.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved