CVE-2020-8445 is a critical vulnerability affecting OSSEC-HIDS versions 2.7 through 3.5.0, where the ossec-analysisd component fails to properly sanitize log messages by removing or encoding terminal control characters and newlines. This flaw allows for the injection of nested events into OSSEC logs and potential obfuscation or command execution when viewed through vulnerable terminal emulators. With a CVSS score of 9.8 (Critical), it presents a high-impact, unauthenticated remote attack vector, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.7, <= 3.5.0CPE matchmatch criteria | cpe:2.3:a:ossec:ossec:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.