CVE-2017-6972
Last modified
CVE-2017-6972 is a vulnerability of currently unknown severity. AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.. EPSS estimates a 14.60% chance of exploitation in the next 30 days.
Description
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alienvault | Ossim | <= 5.3.6 |
| Alienvault | Unified Security Management | <= 5.3.6 |
| Nfsen | Nfsen | <= 1.3.7 |
References
- http://www.securityfocus.com/bid/97016Third Party Advisory, VDB Entry
- https://sourceforge.net/p/nfsen/news/2017/01/nfsen-138-released---security-fix/Third Party Advisory
- https://www.alienvault.com/forums/discussion/8698Vendor Advisory
- http://www.securityfocus.com/bid/97016Third Party Advisory, VDB Entry
- https://sourceforge.net/p/nfsen/news/2017/01/nfsen-138-released---security-fix/Third Party Advisory
- https://www.alienvault.com/forums/discussion/8698Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6972?
How severe is CVE-2017-6972?
How do I fix CVE-2017-6972?
Are you affected by CVE-2017-6972?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
