9.9
CVSSv3

CVE-2017-7175

Published: 10/07/2017 Updated: 13/07/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

NfSen prior to 1.3.8 allows remote malicious users to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).

Vulnerable Product Search on Vulmon Subscribe to Product

nfsen nfsen

Exploits

# Exploit Title: NfSen/AlienVault remote root exploit (command injection in customfmt parameter) # Version: NfSen 136p1, 137 and 137-1~bpo80+1_all Previous versions are also likely to be affected # Version: AlienVault USM/OSSIM < 431 # Date: 2017-07-10 # Vendor Homepage: nfsensourceforgenet/ # Vendor Homepage: wwwalien ...
NfSen version 137 and AlienVault OSSIM version 431 suffer from a customfmt command injection vulnerability ...