ZeroHour

CVE-2017-6972

CVSS 3.0
9.8 critical
EPSS
15%p96
Published
()
Modified
Description

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.

Vendors
alienvaultnfsen
Products
ossim, unified security management, nfsen
Weakness
CWE-273
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.