Vulnerability Details CVE-2017-5198
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 7.2
Products affected by CVE-2017-5198
-
cpe:2.3:a:solarwinds:log_and_event_manager:6.1
-
cpe:2.3:a:solarwinds:log_and_event_manager:6.2
-
cpe:2.3:a:solarwinds:log_and_event_manager:6.2.1
-
cpe:2.3:a:solarwinds:log_and_event_manager:6.3.0