CVE-2021-35223
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.
HIGH · CVSS 8.5
EPSS 0.10768
Schedule remediation
- EPSS ≥ 0.10 - elevated exploitation probability
- EPSS percentile: top 7% of all CVEs by exploitation likelihood
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0