High severity8.8NVD Advisory· Published Mar 22, 2017· Updated May 13, 2026
CVE-2017-6971
CVE-2017-6971
Description
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault ID ENG-104862.
Affected products
3- cpe:2.3:a:alienvault:unified_security_management:*:*:*:*:*:*:*:*Range: <=5.3.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- sourceforge.net/p/nfsen/news/2017/01/nfsen-138-released---security-fix/nvdThird Party Advisory
- www.alienvault.com/forums/discussion/8325/nvdVendor Advisory
- www.alienvault.com/forums/discussion/8698nvdVendor Advisory
- www.exploit-db.com/exploits/42306/nvd
News mentions
0No linked articles in our index yet.