CVE-2015-7840: High severity solarwinds security event manager vulnerability
Published Oct 15, 2015
·Updated
The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature.
Affected Software
1 affected component
SolarWinds Log and Event Manager<=6.1
Event History
Oct 15, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-7840?
CVE-2015-7840 has a high severity rating as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2015-7840?
To fix CVE-2015-7840, you should upgrade SolarWinds Log and Event Manager to version 6.2.0 or later.
3
What software is affected by CVE-2015-7840?
CVE-2015-7840 affects SolarWinds Log and Event Manager versions prior to 6.2.0.
4
What is the nature of the vulnerability in CVE-2015-7840?
The nature of the vulnerability in CVE-2015-7840 involves the command line management console allowing for remote code execution.
5
Can CVE-2015-7840 be exploited remotely?
Yes, CVE-2015-7840 can be exploited remotely by attackers through unspecified vectors involving the ping feature.