CVE-2017-5198: SolarWinds Log And Event Manager
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.
Affected products
- SolarWinds Log And Event Manager: before 6.3.1 (fixed in 6.3.1)
Published 2017-03-24. Last modified 2026-06-17.