vendor:
NfSen/USM/OSSIM
by:
Paul Taylor / Foregenix Ltd
8,4
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: NfSen/USM/OSSIM
Affected Version From: NfSen 1.3.7
Affected Version To: AlienVault 5.3.6
Patch Exists: YES
Related CWE: CVE-2017-6970
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AlienVault USM 5.3.6
2017
Local root exploit affecting NfSen <= 1.3.7, AlienVault USM/OSSIM <= 5.3.6
The web user (in AlienVault USB www-data) has access to the NfSen IPC UNIX domain socket. This can be used to send a crafted command (complete with shell metacharacter injection) to the NfSen Perl components, causing OS command injection in a root privilege context, and therefore can be leverage for privilege escalation from the web user to full root privileges.
Mitigation:
Update to latest version of NfSen/USM/OSSIM.