CVE-2020-35481
CVE-2020-35481 is a critical-severity vulnerability in Solarwinds Serv-u with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 1% (68th percentile)
- Actively exploited: Not listed in CISA KEV
- Affected product: Solarwinds Serv-u
- Published:
- Last modified:
Description
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
Frequently asked questions
- What is CVE-2020-35481?
- SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
- How severe is CVE-2020-35481?
- CVE-2020-35481 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2020-35481 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (68th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-35481?
- CVE-2020-35481 affects Solarwinds Serv-u. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-35481?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2020-35481 published?
- CVE-2020-35481 was published on 2021-02-03 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
More vulnerabilities in Solarwinds Serv-u
- CVE-2026-28321 — Critical (CVSS 9.1): SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write,…
- CVE-2026-28317 — Critical (CVSS 9.1): SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege…
- CVE-2026-28316 — Critical (CVSS 9.1): SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege…
- CVE-2026-28314 — Critical (CVSS 9.1): SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover.…
- CVE-2026-28313 — Critical (CVSS 9.1): SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP…
- CVE-2026-28312 — Critical (CVSS 9.1): SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system…