CVE-2017-6972: Critical severity AlienVault OSSIM vulnerability
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6972?
CVE-2017-6972 is considered a moderate severity vulnerability due to its potential to execute code as root.
How do I fix CVE-2017-6972?
To fix CVE-2017-6972, upgrade AlienVault USM and OSSIM to version 5.3.7 or later, and NfSen to version 1.3.8 or later.
What types of software are affected by CVE-2017-6972?
CVE-2017-6972 affects AlienVault OSSIM versions up to 5.3.6, AlienVault Unified Security Management versions up to 5.3.6, and NfSen versions up to 1.3.7.
Is CVE-2017-6972 related to other vulnerabilities?
Yes, CVE-2017-6972 is a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
What is the impact of CVE-2017-6972?
CVE-2017-6972 allows an attacker to potentially execute NfSen Perl code with elevated privileges, posing a security risk.