Ossec is a modestly represented host-based intrusion detection and log-analysis platform that, despite a narrow product portfolio, occupies a strategic role in security monitoring across enterprise and government deployments. Vulnerabilities affecting the core Ossec agent and web UI skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with recurring weaknesses centered on path traversal, out-of-bounds writes, use-after-free conditions, and input-validation flaws that are endemic to agents with privileged system access and web interfaces. Defenders should prioritize this vendor's security updates given the elevated risk profile and the agent's typical placement in sensitive monitoring infrastructure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ossec over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5284HIGH host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts | Dec 2, 2014 | 7.2 | 35 | NO | YES |
CVE-2020-8443CRITICAL In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning o | Jan 30, 2020 | 9.8 | 32 | NO | NO |
CVE-2020-8447CRITICAL In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs | Jan 30, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-8444CRITICAL In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of ossec-alert formatted ms | Jan 30, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-8445CRITICAL In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many c | Jan 30, 2020 | 9.8 | 29 | NO | NO |
CVE-2015-3222HIGH syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root. | Sep 7, 2017 | 7.0 | 27 | NO | YES |
CVE-2020-8442HIGH In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder componen | Jan 30, 2020 | 8.8 | 25 | NO | NO |
CVE-2021-28040HIGH An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number of opening and closing XML tags is used. Because recursion is | Mar 5, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-19666HIGH The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server. | Nov 29, 2018 | 7.8 | 24 | NO | NO |
CVE-2016-4847MEDIUM Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored re | Apr 20, 2017 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ossec.
Media articles that mention a CVE ID that affects a product developed by Ossec — matched by CVE ID, not by vendor name.