vendor:
NfSen/AlienVault
by:
Paul Taylor / Foregenix Ltd
8,8
CVSS
HIGH
Command Injection
78
CWE
Product Name: NfSen/AlienVault
Affected Version From: NfSen 1.3.6p1, 1.3.7 and 1.3.7-1~bpo80+1_all
Affected Version To: AlienVault 5.3.4
Patch Exists: YES
Related CWE: CVE-2017-6971
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AlienVault USM 5.3.4
2017
NfSen/AlienVault remote root exploit (IPC query command injection)
A remote authenticated attacker (or an attacker with a stolen PHP Session ID) can gain complete control over the system by sending a crafted request containing control characters and shell commands which will be executed as root on a vulnerable system.
Mitigation:
Update to latest version of NfSen/USM/OSSIM.