AlienVault USM Multiple Vulnerabilities


Description   (#Several vulnerabilities were reported in AlienVault USM:#- cross-site scripting when import NBE. A remote attacker could exploit it by enticing their victim into following a specially crafted link in order to upload an arbitrary NBE file thus allowing arbitrary JavaScript code execution. This vulnerability, located in the "/ossim/vulnmeter/import_nbe.php" web page, stems from inconsistent management of temporary files and predictable filenames in the web root and failure to set a "Content-Type header"##- arbitrary code execution. A remote attacker could exploit it by connecting to Erlang daemon 4369 port in order to execute arbitrary code with RabbitMQ privileges. This vulnerability stems from USM which uses a static cookie value stored in "/var/lib/rabbitmq/.erlang.cookie" file.##Proofs of concept are available.)
     
Vulnerable Products   Vulnerable Software:
Unified Security Management (AlienVault) - 4.0, 4.1, 4.10, 4.11, 4.11.1, ..., 5.2, 5.2.1, 5.2.2, 5.2.3, 5.2.4
     
Solution   No solution for the moment.
     
CVE  
     
References   - Security-Assessment : AlienVault USM Multiple Vulnerabilities
http://www.security-assessment.com/files/documents/advisory/AlienVault%20-%20USM%205.2.5%20-%20Multiple%20Vulnerabilities%20-%20Release.pdf
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
XSS - Prevention - POST : suspicious 'meta' tag found in data
3.2.0
XSS - Prevention - POST : suspicious 'img' attribute found in data
3.2.0
XSS - Prevention - POST : suspicious 'style' tag found in data
5.0.0
XSS - Prevention - POST : javascript code found in data
5.0.0
XSS - Prevention - POST : suspicious tag with event found in data
5.0.0
XSS - Prevention - POST : suspicious 'embed' tag found in data
5.0.0
XSS - Prevention - POST : 'location' javascript object found in data
5.0.0
XSS - Prevention - POST : code allowing cookie access found in data
5.0.0
XSS - Prevention - POST : 'script' tag found in data
5.0.0
XSS - Prevention - POST : suspicious 'style' attribute found in data
5.0.0
XSS - Prevention - POST : suspicious 'applet' tag found in data
5.0.0
XSS - Prevention - POST : suspicious 'div' tag found in data
5.0.0
XSS - Prevention - POST : suspicious 'img' attribute found in data
5.0.0
XSS - Prevention - POST : suspicious 'meta' tag found in data
5.0.0
XSS - Prevention - POST : suspicious 'object' tag found in data
5.0.0
XSS - Prevention - POST : suspicious 'iframe' tag found in data
5.0.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2016-06-27 

 Target Type 
Server 

 Possible exploit 
Remote