CVE-2017-5199: High severity SolarWinds Log and Event Manager vulnerability
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Set the editbanner feature to disabled for SolarWinds LEM (SIEM) versions up to and including 6.3.1.
SolarWinds LEM (SIEM) editbanner feature = disabled - Compensating control
Disable or remove the SolarWinds LEM (SIEM) editbanner feature that allows remote authenticated users to modify /usr/local/contego/scripts/mgrconfig.pl (vulnerable through 6.3.1).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5199?
CVE-2017-5199 is classified as a high severity vulnerability that allows remote authenticated users to execute arbitrary code.
How do I fix CVE-2017-5199?
To mitigate CVE-2017-5199, users should upgrade SolarWinds LEM to version 6.3.2 or later.
Who is affected by CVE-2017-5199?
CVE-2017-5199 affects all versions of SolarWinds Log and Event Manager prior to 6.3.2.
What type of vulnerability is CVE-2017-5199?
CVE-2017-5199 is a code execution vulnerability stemming from the editbanner feature in SolarWinds LEM.
Can CVE-2017-5199 be exploited remotely?
Yes, CVE-2017-5199 can be exploited by remote authenticated users.