Vulnerabilities
Vulnerable Software
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
CVSS Score
9.8
EPSS Score
0.025
Published
2018-03-14
The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.
CVSS Score
6.7
EPSS Score
0.001
Published
2017-05-23
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.
CVSS Score
7.2
EPSS Score
0.062
Published
2017-05-23
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.
CVSS Score
10.0
EPSS Score
0.055
Published
2014-08-21
SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.
CVSS Score
7.5
EPSS Score
0.004
Published
2014-08-21
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
CVSS Score
10.0
EPSS Score
0.135
Published
2014-08-21
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVSS Score
6.5
EPSS Score
0.247
Published
2014-08-21
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request.
CVSS Score
10.0
EPSS Score
0.114
Published
2014-06-18
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.
CVSS Score
10.0
EPSS Score
0.114
Published
2014-06-18
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.
CVSS Score
7.8
EPSS Score
0.076
Published
2014-06-18


Contact Us

Shodan ® - All rights reserved