CVE-2017-6970 Information

Description

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket aka AlienVault ID ENG-104863.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://sourceforge.net/p/nfsen/news/2017/01/nfsen-138-released—security-fix/ https://www.alienvault.com/forums/discussion/8325/ https://www.alienvault.com/forums/discussion/8698 https://www.exploit-db.com/exploits/42305/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.4

Share on: