vendor:
Solarwinds Virtualization Manager
by:
Nate Kettlewell, Depth Security
7,8
CVSS
HIGH
Security Misconfiguration
269
CWE
Product Name: Solarwinds Virtualization Manager
Affected Version From: < 6.3.1
Affected Version To: 6.3.1
Patch Exists: YES
Related CWE: CVE-2016-3643
CPE: a:solarwinds:virtualization_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Solarwinds Virtualization Manager
Depth Security discovered a vulnerability in Solarwinds Virtualization Manager appliance. This attack requires a user to have an operating system shell on the vulnerable appliance. The vulnerability exists due to the miconfiguration of sudo in that it allows any local user to use sudo to execute commands as the superuser. A local attacker can obtain root privileges to the operating system regardless of privilege level.
Mitigation:
Solarwinds has released a hotfix to remediate this vulnerability on existing installations.