VYPR

Log \& Event Manager

Sign in to watch

by SolarWinds

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-7722Cri0.7210.00.50Apr 12, 2017In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.
CVE-2017-7647Hig0.578.80.03Apr 10, 2017SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.
CVE-2017-7646Med0.426.50.01Apr 10, 2017SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.