// For flags

CVE-2014-5504

SolarWinds Log and Event Manager Static Credential Remote Code Execution Vulnerability

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via unspecified vectors, related to HyperSQL.

SolarWinds Log And Event Manager anterior a 6.0 utiliza credenciales 'estáticas', lo que facilita a atacantes remotos obtener acceso a la base de datos y ejecutar código arbitrario a través de vectores no especificados, relacionado con HyperSQL.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of SolarWinds Log and Event Manager. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the usage of HyperSQL. The issue lies in the usage of static credentials to access the database. A remote attacker can use this vulnerability to execute code under the context of the database.

*Credits: G. Geshev
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-08-28 CVE Reserved
  • 2014-09-03 CVE Published
  • 2023-09-29 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Solarwinds
Search vendor "Solarwinds"
Log And Event Manager
Search vendor "Solarwinds" for product "Log And Event Manager"
<= 5.7.0
Search vendor "Solarwinds" for product "Log And Event Manager" and version " <= 5.7.0"
-
Affected
Solarwinds
Search vendor "Solarwinds"
Log And Event Manager
Search vendor "Solarwinds" for product "Log And Event Manager"
5.2.0
Search vendor "Solarwinds" for product "Log And Event Manager" and version "5.2.0"
-
Affected
Solarwinds
Search vendor "Solarwinds"
Log And Event Manager
Search vendor "Solarwinds" for product "Log And Event Manager"
5.4.0
Search vendor "Solarwinds" for product "Log And Event Manager" and version "5.4.0"
-
Affected
Solarwinds
Search vendor "Solarwinds"
Log And Event Manager
Search vendor "Solarwinds" for product "Log And Event Manager"
5.5.0
Search vendor "Solarwinds" for product "Log And Event Manager" and version "5.5.0"
-
Affected
Solarwinds
Search vendor "Solarwinds"
Log And Event Manager
Search vendor "Solarwinds" for product "Log And Event Manager"
5.6.0
Search vendor "Solarwinds" for product "Log And Event Manager" and version "5.6.0"
-
Affected