PT-2020-20146 · Trend Micro · Ossec-Hids

CVE-2020-8446

·

Published

2020-01-30

·

Updated

2022-09-12

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OSSEC-HIDS versions 2.7 through 3.5.0
Description The server component responsible for log analysis, ossec-analysisd, is vulnerable to path traversal with write access via crafted syscheck messages written directly to the analysisd UNIX domain socket by a local user.
Recommendations For OSSEC-HIDS versions 2.7 through 3.5.0, consider restricting access to the analysisd UNIX domain socket to prevent local users from writing crafted syscheck messages. As a temporary workaround, consider disabling the syscheck feature until a patch is available. Restrict write access to sensitive directories and files to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8446

Affected Products

Ossec-Hids