Advisory Details

November 10th, 2015

AlienVault Unified Security Management Local Privilege Escalation Vulnerability

ZDI-15-548
ZDI-CAN-3020

CVE ID
CVSS SCORE 6.9, AV:L/AC:M/Au:N/C:C/I:C/A:C
AFFECTED VENDORS AlienVault
AFFECTED PRODUCTS Unified Security Management
VULNERABILITY DETAILS


This vulnerability allows local attackers to escalate privileges to root on vulnerable installations of AlienVault Unified Security Management. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the configuration of the server and database. A local attacker in the alienvault group can read the database password and schedule, as root, a custom report that can include shell commands. This vulnerability can be leveraged by a local attacker to execute arbitrary code as root.

ADDITIONAL DETAILS AlienVault has issued an update to correct this vulnerability. More details can be found at:
https://www.alienvault.com/forums/discussion/5127/
DISCLOSURE TIMELINE
  • 2015-06-25 - Vulnerability reported to vendor
  • 2015-11-10 - Coordinated public release of advisory
CREDIT agix
BACK TO ADVISORIES