CVE Published: 16/12/2022 |
CVE Updated: 04/08/2024 |
CVE Year: 2021 Source: SolarWinds |
Vendor: SolarWinds |
Product: Serv-U FTP Server Status : PUBLISHED
CVE-2021-35252 Description
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N