7
CVSSv3

CVE-2015-3222

Published: 07/09/2017 Updated: 13/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 695
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

syscheck/seechanges.c in OSSEC 2.7 up to and including 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ossec ossec 2.8.0

ossec ossec 2.7.1

ossec ossec 2.8.1

ossec ossec 2.7.0

Exploits

Fix for CVE-2015-3222 which allows for root escalation via syscheck - githubcom/ossec/ossec-hids/releases/tag/282 Affected versions: 27 - 281 Beginning is OSSEC 27 (d88cf1c9) a feature was added to syscheck, which is the daemon that monitors file changes on a system, called "report_changes" This feature is only available on *NIX s ...
OSSEC versions 27 through 281 suffer from a local root escalation vulnerability ...