RULE(RULE ID:321983)

Rule General Information
Release Date: 2019-06-25
Rule Name: OSSIM AlienVault av-centerd Util.pm remote_task Arbitrary Command Execution Vulnerability (CVE-2014-5210)
Severity:
CVE ID:
Rule Protection Details
Description: The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:69239
http://forums.alienvault.com/discussion/2690
ZeroDayInitiative:ZDI-14-294
ZeroDayInitiative:ZDI-14-295
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://forums.alienvault.com/discussion/2690