peter bassill · operator
$ cve CVE-2016-8580 JSON

CVE-2016-8580 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.86% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploityes
Published2016-10-28
Last modified2026-06-17

Affected (2)

VendorProduct
alienvaultopen source security information and event management
alienvaultunified security management

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD