CVE-2014-4152
AlienVault OSSIM < 4.8.0 - Remote Code Execution via Crafted remote_task Request
Title source: llmDescription
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://forums.alienvault.com/discussion/2806
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-206/
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/59112
Scores
EPSS
0.0578
EPSS Percentile
92.2%
Details
CWE
CWE-94
Status
published
Products (7)
alienvault/open_source_security_information_management
4.0
alienvault/open_source_security_information_management
4.3.3
alienvault/open_source_security_information_management
4.4
alienvault/open_source_security_information_management
4.5
alienvault/open_source_security_information_management
4.6
alienvault/open_source_security_information_management
4.6.1
alienvault/open_source_security_information_management
< 4.7.0
Published
Jun 18, 2014
Tracked Since
Feb 18, 2026