← Vulnerability feed

Vulnerability record · CVE-2014-3804 · published 13 June 2014

CVE-2014-3804: AlienVault OSSIM av-centerd SOAP service command injection

Alienvault · Open Source Security Information Management

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 fails to properly validate input in several request types, allowing remote command injection. An unauthenticated attacker can execute arbitrary commands on the OSSIM server, which is a security management platform and therefore a high-value target.

10.0 CVSS 2.0 High EPSS 72% · top 0.6% CWE-94 · Code injection
10.0CVSS 2.0 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than CVE-2014-3805.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS base score of 10.0 and public exploit code makes this an urgent risk for any unpatched OSSIM deployment.

What it is

The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 fails to properly validate input in several request types, allowing remote command injection. An unauthenticated attacker can execute arbitrary commands on the OSSIM server, which is a security management platform and therefore a high-value target.

Impact

An attacker gains remote code execution with the privileges of the av-centerd service, leading to full compromise of the OSSIM host and potentially the monitored environment. This can result in data theft, configuration tampering, or use of the host as a pivot point.

Attack surface

The flaw is reachable over the network via the av-centerd SOAP service, as indicated by the CVSS vector AV:N/AC:L/Au:N. No authentication or user interaction is required.

Exploitation

Exploit code is publicly available (Exploit-DB 42708), and EPSS indicates a high probability of exploitation activity (0.72376, 99.41st percentile). The CVE is not listed in CISA KEV.

What to do

  • Upgrade AlienVault OSSIM to version 4.7.0 or later.
  • Restrict network access to the av-centerd SOAP service to trusted management hosts only.
  • If patching is not immediately possible, disable or firewall the av-centerd service until the upgrade can be applied.
  • Monitor for and investigate any unexpected outbound connections or process executions on OSSIM servers.

Detection

  • Inspect SOAP requests to av-centerd for suspicious parameters such as update_system_info_debian_package, ossec_task, set_ossim_setup, or sync_rserver containing shell metacharacters.
  • Monitor process creation on OSSIM hosts for unexpected child processes spawned by the av-centerd service.
  • Review network logs for connections to the av-centerd SOAP port from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-3804 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-5158Alienvault open source security information management code injection vulnerabilityThe (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to exe…EPSS 3.7%10.0CVE-2014-5210Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (…EPSS 15%10.0CVE-2014-4151Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a craft…EPSS 7.3%10.0CVE-2014-4152Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, rel…EPSS 5.8%10.0CVE-2014-3805Alienvault open source security information management code injection vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2)…EPSS 13%9.8CVE-2018-7279Alienvault open source security information management vulnerabilityA remote code execution issue was discovered in AlienVault USM and OSSIM before 5.5.1.EPSS 2.4%7.8CVE-2014-4153Alienvault open source security information management information exposure vulnerabilityThe av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.EPSS 7.4%7.5CVE-2013-6056Alienvault open source security information management path traversal vulnerabilityOSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerabilityEPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2014-3804), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.