CVE-2015-3446: Code Injection
Published May 1, 2015
·Updated
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg).
Affected Software
1 affected component
AlienVault Unified Security Management<=4.14
Remediation
Patch Available
Event History
May 1, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3446?
CVE-2015-3446 is classified as a high-severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2015-3446?
To fix CVE-2015-3446, upgrade AlienVault Unified Security Management to version 4.15 or later.
3
What can be exploited in CVE-2015-3446?
CVE-2015-3446 can be exploited through a crafted plugin configuration (.cfg) file to execute arbitrary Python code.
4
Which versions of AlienVault Unified Security Management are affected by CVE-2015-3446?
CVE-2015-3446 affects AlienVault Unified Security Management versions prior to 4.15.
5
What type of attack does CVE-2015-3446 enable?
CVE-2015-3446 enables remote attackers to execute arbitrary code on the affected system.