Back

CVE-2017-7722

CRITICAL

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.

Published: Apr 12, 2017 Modified: Jun 17, 2026
CWE-77

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
solarwinds log_\&_event_manager 6.3.1

GitHub Security Advisory GHSA-fgrm-fppr-4fwr

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 12.73%

Top 4% most likely to be exploited

Threat Score 43.8 / 100

Data Sources

NVD EPSS GitHub