CVE-2014-5158: Code Injection
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5158?
CVE-2014-5158 is considered a high-severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2014-5158?
To fix CVE-2014-5158, users should upgrade to AlienVault OSSIM version 4.6.0 or later.
What systems are affected by CVE-2014-5158?
CVE-2014-5158 affects AlienVault OSSIM versions up to 4.5.0, as well as specific versions from 1.0.4 to 4.4.
What impact does CVE-2014-5158 have on security?
CVE-2014-5158 allows remote attackers to execute arbitrary commands, posing a significant threat to system integrity and confidentiality.
Can CVE-2014-5158 be exploited without authentication?
Yes, CVE-2014-5158 can be exploited by remote attackers without requiring prior authentication, making it particularly dangerous.