CVE-2014-5210: Code Injection
Published Aug 21, 2014
·Updated
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remotetask or (2) getlicense request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.
Affected Software
29 affected components
AlienVault Open Source Security Information Management<=4.6.1
AlienVault Open Source Security Information Management=1.0.4
AlienVault Open Source Security Information Management=1.0.6
AlienVault Open Source Security Information Management=2.1
AlienVault Open Source Security Information Management=2.1.2
AlienVault Open Source Security Information Management=2.1.5
AlienVault Open Source Security Information Management=2.1.5-1
AlienVault Open Source Security Information Management=2.1.5-2
AlienVault Open Source Security Information Management=2.1.5-3
AlienVault Open Source Security Information Management=3.1
AlienVault Open Source Security Information Management=3.1.9
AlienVault Open Source Security Information Management=3.1.10
AlienVault Open Source Security Information Management=3.1.12
AlienVault Open Source Security Information Management=4.0
AlienVault Open Source Security Information Management=4.0.3
AlienVault Open Source Security Information Management=4.0.4
AlienVault Open Source Security Information Management=4.1
AlienVault Open Source Security Information Management=4.1.2
AlienVault Open Source Security Information Management=4.1.3
AlienVault Open Source Security Information Management=4.2
AlienVault Open Source Security Information Management=4.2.2
AlienVault Open Source Security Information Management=4.2.3
AlienVault Open Source Security Information Management=4.3
AlienVault Open Source Security Information Management=4.3.1
AlienVault Open Source Security Information Management=4.3.2
AlienVault Open Source Security Information Management=4.3.3
AlienVault Open Source Security Information Management=4.4
AlienVault Open Source Security Information Management=4.5
AlienVault Open Source Security Information Management=4.6
Event History
Aug 21, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5210?
CVE-2014-5210 has a severity rating that allows remote attackers to execute arbitrary commands.
2
How do I fix CVE-2014-5210?
To fix CVE-2014-5210, upgrade to AlienVault OSSIM version 4.7.0 or higher.
3
What software is affected by CVE-2014-5210?
CVE-2014-5210 affects AlienVault OSSIM versions prior to 4.7.0.
4
Can CVE-2014-5210 lead to data breach?
Yes, CVE-2014-5210 can potentially lead to unauthorized access and data breaches due to command execution capabilities.
5
What types of requests are exploited in CVE-2014-5210?
CVE-2014-5210 can be exploited through crafted requests to the remote_task or get_license functionalities.