← back
CVE-2017-7722

CVE-2017-7722

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 13%
from disclosure to weapon0 days
Published on NVDApr 12
metasploitMar 17
exploitation probability
13%top 4% of all CVEs
observed exploitation
nono source reports it
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.
Affected products
n/a · n/a