PT-2017-3092 · Solarwinds · Solarwinds Log & Event Manager
Mehmet Ince
·
Published
2017-03-17
·
Updated
2017-04-21
·
CVE-2017-7722
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SolarWinds Log & Event Manager (LEM) versions prior to 6.3.1 Hotfix 4
Description
The issue is related to the restrictssh feature in the menuing script of SolarWinds Log & Event Manager (LEM). An attacker can exploit this to escape from the restricted shell by accessing the SSH service with the default username and password,
cmc and password. This allows a remote attacker to bypass shell restrictions, elevate privileges, and execute commands with root privileges.Recommendations
For SolarWinds Log & Event Manager (LEM) versions prior to 6.3.1 Hotfix 4, update to version 6.3.1 Hotfix 4 or later to resolve the issue.
As a temporary workaround, consider changing the default username and password for SSH access to prevent exploitation.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solarwinds Log & Event Manager