First published: Fri Mar 24 2017(Updated: )
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SolarWinds Security Event Manager | <6.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5198 has a critical severity rating due to the potential for local users to gain root access.
To fix CVE-2017-5198, upgrade SolarWinds LEM to version 6.3.1 or later to correct the incorrect sudo configuration.
CVE-2017-5198 affects all versions of SolarWinds Log and Event Manager prior to version 6.3.1.
CVE-2017-5198 is a local privilege escalation vulnerability due to misconfiguration of system permissions.
An attacker can exploit CVE-2017-5198 to edit scripts and potentially gain unauthorized root access on the affected system.