CVE-2014-4152: Alienvault Open Source Security Information Management
High severity, CVSS 10.0. EPSS: 5.8% chance of exploitation in the next 30 days.
The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.
Affected products
- Alienvault Open Source Security Information Management: up to and including 4.7.0; version 4.0 only; version 4.3.3 only; version 4.4 only; version 4.5 only; version 4.6 only; …
Published 2014-06-18. Last modified 2026-06-17.