CVE-2014-5158

AlienVault OSSIM < 4.6.0 - Remote Code Execution via av-centerd SOAP Service and Backup Command

Title source: llm
STIX 2.1

Description

The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-273/
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-272/

Scores

EPSS 0.0368
EPSS Percentile 88.3%

Details

CWE
CWE-94
Status published
Products (27)
alienvault/open_source_security_information_management 1.0.4
alienvault/open_source_security_information_management 1.0.6
alienvault/open_source_security_information_management 2.1
alienvault/open_source_security_information_management 2.1.2
alienvault/open_source_security_information_management 2.1.5
alienvault/open_source_security_information_management 2.1.5-1
alienvault/open_source_security_information_management 2.1.5-2
alienvault/open_source_security_information_management 2.1.5-3
alienvault/open_source_security_information_management 3.1
alienvault/open_source_security_information_management 3.1.9
... and 17 more
Published Aug 21, 2014
Tracked Since Feb 18, 2026