VYPR
Unrated severityNVD Advisory· Published Jun 13, 2014· Updated May 6, 2026

CVE-2014-3805

CVE-2014-3805

Description

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.

Affected products

17
  • cpe:2.3:a:alienvault:open_source_security_information_management:*:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:alienvault:open_source_security_information_management:*:*:*:*:*:*:*:*range: <=4.6.1
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.2:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.3:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.4:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:alienvault:open_source_security_information_management:4.6:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.