CVE-2017-6971
HIGH 9.0EPSS 16.2%
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault ID ENG-104862.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.0 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C - EPSS
- 16.18% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2017-03-22
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- KeyStrOke95/nfsen_1.3.7_CVE-2017-69710★ · 2019-04-24
- patrickfreed/nfsen-exploit4★ · 2017-04-10