CVE-2016-7955
9.8
CRITICAL · CVSS 3.0 · EPSS 6.4% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the application, or execute arbitrary code as root via an "AV Report Scheduler" HTTP User-Agent header.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.41% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-03-15 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| alienvault | ossim |
| alienvault | unified security management |
References
- http://www.securityfocus.com/archive/1/540224/100/0/threaded
- http://www.zerodayinitiative.com/advisories/ZDI-16-517/
- https://www.alienvault.com/forums/discussion/7765/alienvault-v5-3-1-hotfix
- http://www.securityfocus.com/archive/1/540224/100/0/threaded
- http://www.zerodayinitiative.com/advisories/ZDI-16-517/
- https://www.alienvault.com/forums/discussion/7765/alienvault-v5-3-1-hotfix
→ the Explorer · watch your stack · NVD