Vulnerability Details CVE-2017-14956
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send out any report via email to a given address (either in PDF or XLS format). Since there is no anti-CSRF token protecting this functionality, it is vulnerable to Cross-Site Request Forgery attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.2%
CVSS Severity
CVSS v3 Score 5.7
CVSS v2 Score 3.5
Products affected by CVE-2017-14956
-
cpe:2.3:a:alienvault:unified_security_management:4.14
-
cpe:2.3:a:alienvault:unified_security_management:5.2
-
cpe:2.3:a:alienvault:unified_security_management:5.3
-
cpe:2.3:a:alienvault:unified_security_management:5.3.1
-
cpe:2.3:a:alienvault:unified_security_management:5.3.6
-
cpe:2.3:a:alienvault:unified_security_management:5.4.2