CVE-2021-25276
CVSS V2 Low 3.6
CVSS V3 High 7.1
Description
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a user with a C:\ home directory, then the attacker obtains access to read or replace arbitrary files with LocalSystem privileges.
Overview
- CVE ID
- CVE-2021-25276
- Assigner
- cve@mitre.org
- Vulnerability Status
- Analyzed
- Published Version
- 2021-02-03T17:15:16
- Last Modified Date
- 2022-07-12T17:42:04
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:* | 1 | OR | 15.2.2 | |
cpe:2.3:a:solarwinds:serv-u:15.2.2:-:*:*:*:*:*:* | 1 | OR |
CVSS Version 2
- Version
- 2.0
- Vector String
- AV:L/AC:L/Au:N/C:P/I:P/A:N
- Access Vector
- LOCAL
- Access Compatibility
- LOW
- Authentication
- NONE
- Confidentiality Impact
- PARTIAL
- Integrity Impact
- PARTIAL
- Availability Impact
- NONE
- Base Score
- 3.6
- Severity
- LOW
- Exploitability Score
- 3.9
- Impact Score
- 4.9
CVSS Version 3
- Version
- 3.1
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Vector
- LOCAL
- Attack Compatibility
- LOW
- Privileges Required
- LOW
- User Interaction
- NONE
- Scope
- UNCHANGED
- Confidentiality Impact
- HIGH
- Availability Impact
- NONE
- Base Score
- 7.1
- Base Severity
- HIGH
- Exploitability Score
- 1.8
- Impact Score
- 5.2
References
Reference URL | Reference Tags |
---|---|
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/full-system-control-with-new-solarwinds-orion-based-and-serv-u-ftp-vulnerabilities/ | Exploit Third Party Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2021-25276 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25276 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-05-10 07:23:50 | Added to TrackCVE | |||
2022-12-05 21:18:57 | 2021-02-03T17:15Z | 2021-02-03T17:15:16 | CVE Published Date | updated |
2022-12-05 21:18:57 | 2022-07-12T17:42:04 | CVE Modified Date | updated | |
2022-12-05 21:18:57 | Analyzed | Vulnerability Status | updated |