CVE-2017-6972 is a critical privilege escalation vulnerability affecting AlienVault USM and OSSIM prior to version 5.3.7, and NfSen prior to 1.3.8. The flaw stems from improper privilege dropping, causing the NfSen Perl code to execute unnecessarily as root. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, and availability) with low attack complexity. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-42314) details a command injection exploit for NfSen < 1.3.7 / AlienVault OSSIM 4.3.1, indicating public exploit code availability. Despite this, there is no recorded community discussion or media coverage, suggesting limited public awareness or active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.3.6CPE matchmatch criteria | cpe:2.3:a:alienvault:ossim:*:*:*:*:*:*:*:* | ||
<= 5.3.6CPE matchmatch criteria | cpe:2.3:a:alienvault:unified_security_management:*:*:*:*:*:*:*:* | ||
<= 1.3.7CPE matchmatch criteria | cpe:2.3:a:nfsen:nfsen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.