CVE-2017-6972: Alienvault Ossim

Critical severity, CVSS 9.8. EPSS: 14.6% chance of exploitation in the next 30 days.

AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.

Affected products

  • Alienvault Ossim: up to and including 5.3.6
  • Alienvault Unified Security Management: up to and including 5.3.6
  • Nfsen Nfsen: up to and including 1.3.7

Published 2017-03-22. Last modified 2026-06-17.