CVE-2014-4152: Alienvault Open Source Security Information Management

High severity, CVSS 10.0. EPSS: 5.8% chance of exploitation in the next 30 days.

The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.

Affected products

  • Alienvault Open Source Security Information Management: up to and including 4.7.0; version 4.0 only; version 4.3.3 only; version 4.4 only; version 4.5 only; version 4.6 only; …

Published 2014-06-18. Last modified 2026-06-17.