CVE-2020-8446: Path Traversal
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to path traversal (with write access) via crafted syscheck messages written directly to the analysisd UNIX domain socket by a local user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8446?
CVE-2020-8446 has a medium severity rating due to its potential for path traversal attacks that allow local users to write to unauthorized file locations.
How does CVE-2020-8446 affect affected versions of OSSEC?
CVE-2020-8446 allows a local user to exploit the vulnerability in OSSEC-HIDS versions 2.7 through 3.5.0 by sending crafted messages to the analysisd UNIX domain socket.
How do I fix CVE-2020-8446?
To fix CVE-2020-8446, upgrade OSSEC-HIDS to a version later than 3.5.0 where the vulnerability has been patched.
Who is impacted by CVE-2020-8446?
Local users of OSSEC-HIDS versions 2.7 through 3.5.0 are impacted by CVE-2020-8446 due to their ability to send crafted syscheck messages.
What type of vulnerability is CVE-2020-8446?
CVE-2020-8446 is a path traversal vulnerability that allows unauthorized file access through crafted messages.