CVE-2017-5198: SolarWinds Log And Event Manager

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.

Affected products

  • SolarWinds Log And Event Manager: before 6.3.1 (fixed in 6.3.1)

Published 2017-03-24. Last modified 2026-06-17.