← Back to CVE List
Vulnerability Intelligence Report

CVE-2017-7722

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:12.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
solarwinds log_\&_event_manager 6.3.1

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
12.730%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2017-04-12T00:00:00
Published2017-04-12T16:00:00
Last Updated2024-09-17T00:56:33

LINK COPIED TO CLIPBOARD