CVE-2014-3804: Code Injection
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) updatesysteminfodebianpackage, (2) ossectask, (3) setossimsetup adminip, (4) syncrserver, or (5) setossimsetup frameworkip request, a different vulnerability than CVE-2014-3805.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3804?
CVE-2014-3804 is considered to be a high-severity vulnerability allowing arbitrary command execution.
How do I fix CVE-2014-3804?
To fix CVE-2014-3804, upgrade AlienVault OSSIM to version 4.7.0 or later.
What versions of AlienVault OSSIM are affected by CVE-2014-3804?
CVE-2014-3804 affects AlienVault OSSIM versions prior to 4.7.0, including 4.0 to 4.6.1.
What type of vulnerabilities are associated with CVE-2014-3804?
CVE-2014-3804 allows remote attackers to exploit several functions via crafted SOAP requests.
Is remote code execution possible with CVE-2014-3804?
Yes, CVE-2014-3804 allows remote code execution through unauthorized SOAP service requests.