Description
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
No analysis available yet.
Remediation
Vendor Solution
SolarWinds advises to upgrade to the latest version of Serv-U 15.3.2 once became generally available.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21895 | Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext. |
References
History
Thu, 17 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2025-04-17T20:18:01.478Z
Reserved: 2021-06-22T00:00:00.000Z
Link: CVE-2021-35252
Updated: 2024-08-04T00:33:51.290Z
Status : Modified
Published: 2022-12-16T16:15:16.297
Modified: 2024-11-21T06:12:09.607
Link: CVE-2021-35252
No data.
OpenCVE Enrichment
No data.
EUVD