Wazuh.host-deny.Command.Injection
Description
This indicates an attack attempt to exploit a Command Injection Vulnerability in Wazuh.
The vulnerability is due to improper validation of user-supplied inputs. A remote attacker could exploit this vulnerability by sending a crafted request to the target server. Successfully exploitation could result in command execution on the server or agent hosts.
Affected Products
Wazuh prior to 4.7.2
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/wazuh/wazuh/security/advisories/GHSA-mjq2-xf8g-68vw
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |