Advisory Details

June 13th, 2014

AlienVault OSSIM av-centerd Util.pm get_file Information Disclosure Vulnerability

ZDI-14-207
ZDI-CAN-2289

CVE ID CVE-2014-4153
CVSS SCORE 7.8, AV:N/AC:L/Au:N/C:C/I:N/A:N
AFFECTED VENDORS AlienVault
AFFECTED PRODUCTS OSSIM
VULNERABILITY DETAILS


This vulnerability allows remote attackers to obtain sensitive information on vulnerable installations of AlienVault OSSIM. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the av-centerd SOAP service. The issue lies within the improper handling of a parameter in get_file requests. An attacker can leverage this vulnerability to read arbitrary files from the underlying OS with root privileges.

ADDITIONAL DETAILS AlienVault has issued an update to correct this vulnerability. More details can be found at:
http://forums.alienvault.com/discussion/2806
DISCLOSURE TIMELINE
  • 2014-04-18 - Vulnerability reported to vendor
  • 2014-06-13 - Coordinated public release of advisory
CREDIT HP Zero Day Initiative
BACK TO ADVISORIES