CVE-2012-5520

high
Published 2012-11-26 · Modified 2026-04-29
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1) IP address or (2) port number field in an OMP request.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openvas.org/OVSA20121112.html

Application impact

VendorProductVersionsFixed
openvasopenvas_manager3.0
openvasopenvas_manager3.0.0
openvasopenvas_manager3.0.1
openvasopenvas_manager3.0.2
openvasopenvas_manager3.0.3

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.