CVE-2019-12181
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
17/06/2019
Last modified:
30/01/2023
Description
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:solarwinds:serv-u_ftp_server:*:*:*:*:*:linux:*:* | 15.1.7 (excluding) | |
| cpe:2.3:a:solarwinds:serv-u_mft_server:*:*:*:*:*:linux:*:* | 15.1.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/153333/Serv-U-FTP-Server-15.1.6-Privilege-Escalation.html
- http://packetstormsecurity.com/files/153505/Serv-U-FTP-Server-prepareinstallation-Privilege-Escalation.html
- https://blog.vastart.dev/2019/06/cve-2019-12181-serv-u-exploit-writeup.html
- https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-1-7_release_notes.htm
- https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-Potential-elevation-of-privileges-on-Linux-systems



