PatchSiren

PatchSiren cyber security CVE debrief

CVE-2021-35247 SolarWinds CVE debrief

CVE-2021-35247 is a SolarWinds Serv-U improper input validation vulnerability that was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on 2022-01-21. The KEV listing means CISA considered it actively exploited and set a remediation due date of 2022-02-04. The supplied corpus does not include a CVSS score, so defensive prioritization should be driven by the KEV status and vendor guidance rather than severity scoring alone.

Vendor
SolarWinds
Product
Serv-U
CVSS
MEDIUM 4.3
CISA KEV
Listed
Original CVE published
2022-01-21
Original CVE updated
2022-01-21
Advisory published
2022-01-21
Advisory updated
2022-01-21

Who should care

Organizations that use SolarWinds Serv-U, along with security operations, vulnerability management, and patch management teams responsible for remediating KEV-listed vulnerabilities.

Technical summary

The available source material identifies the issue as an improper input validation vulnerability in SolarWinds Serv-U. Beyond that classification, the supplied corpus does not provide exploit mechanics, affected versions, or impact details. The key defensive signal is CISA’s KEV inclusion, which indicates known exploitation and a need for prioritized remediation.

Defensive priority

High. CISA listed this CVE in the KEV catalog on the same date shown in the supplied timeline, with a remediation due date of 2022-02-04. KEV-listed vulnerabilities should be treated as urgent patching priorities.

Recommended defensive actions

  • Inventory all SolarWinds Serv-U deployments and determine which instances are exposed or still in service.
  • Apply SolarWinds updates per vendor instructions as soon as possible.
  • Track remediation against the CISA KEV due date context and confirm closure in vulnerability management records.
  • Review the official vendor and CISA references for any version-specific remediation guidance.
  • Validate that patched systems are current and that any residual Serv-U instances are documented for follow-up.

Evidence notes

Source corpus identifies the vulnerability as SolarWinds Serv-U improper input validation. CISA’s KEV metadata lists vendorProject SolarWinds, product Serv-U, dateAdded 2022-01-21, dueDate 2022-02-04, and requiredAction: 'Apply updates per vendor instructions.' The supplied corpus does not provide a CVSS score or additional technical impact details. Official links provided: CVE.org record, NVD detail, CISA KEV catalog, and the CISA source JSON.

Sources and references

Verified primary and authoritative sources

  • CVE-2021-35247 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2021-35247

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2021-35247 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2021-35247

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.