Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SolarWinds Log and Event Manager 安全漏洞
Vulnerability Description
SolarWinds Log and Event Manager(LEM,又名SIEM)是美国SolarWinds公司的一款日志与事件管理器,它提供实时日志分析、内存事件关联和威胁攻击响应等功能。 SolarWinds LEM 6.3.1之前的版本中存在安全漏洞,该漏洞源于程序中存在错误的sudo配置。本地攻击者可通过编辑/usr/local/contego/scripts/hostname.sh文件利用该漏洞获取root访问权限。
CVSS Information
N/A
Vulnerability Type
N/A