Unified Security Management

Vendor:

First CVE: May 1, 2015 · Active for 11 years

12
Total CVEs
More Total CVEs than 91% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Unified Security Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2015
11 years ago
Most Recent CVE
Mar 14, 2018
3,057 days ago

CVE Severity & Scoring

Unified Security Management12 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local1 (8.3%)
Network10 (83.3%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None7 (58.3%)
Unknown1 (8.3%)
Required4 (33.3%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None8 (66.7%)
Unknown1 (8.3%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read loc
Oct 28, 20169.874NOYES
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945
Mar 22, 20179.850NOYES
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged
Oct 28, 20166.149NOYES
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via
Mar 22, 20178.846NOYES
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic met
Oct 28, 20169.839NOYES
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-1048
Mar 22, 20178.435NOYES
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and co
Mar 15, 20179.834NONO
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an e
Oct 18, 20175.731NOYES
A remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.
Mar 14, 20189.829NONO
The Framework Daemon in AlienVault Unified Security Management before 4.15 allows remote attackers to execute arbitrary Python code via a crafted plugin configuration file (.cfg).
May 1, 20159.323NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
16.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
58.3% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Unified Security Management

Top CWEs

Versions

No cataloged versions.