CVE-2017-6970: OS Command Injection
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6970?
CVE-2017-6970 is classified as a critical vulnerability due to its potential to allow local users to execute arbitrary commands with elevated privileges.
Who is affected by CVE-2017-6970?
CVE-2017-6970 affects local users of AlienVault USM and OSSIM versions before 5.3.7 and NfSen versions before 1.3.8.
How do I fix CVE-2017-6970?
To mitigate CVE-2017-6970, upgrade AlienVault USM and OSSIM to version 5.3.7 or later, and NfSen to version 1.3.8 or later.
What types of attacks can be executed due to CVE-2017-6970?
CVE-2017-6970 can be exploited to execute arbitrary commands, compromising the security of the affected systems.
Is there a workaround for CVE-2017-6970?
There are no specific workarounds for CVE-2017-6970, and the recommended action is to apply the relevant software updates to mitigate the vulnerability.