Impact
Wazuh actively runs system‑level commands in response to alerts. In several active‑response scripts the input fields srcip and dstuser are passed directly to tools such as pfctl, npfctl, ipfw, route, netsh, and passwd without validation or proper quoting. Consequently an attacker who can inject crafted log events can supply arbitrary command arguments that are executed with root privileges. This allows the attacker to run arbitrary code, disable user accounts, or alter firewall rules, directly compromising confidentiality, integrity, and availability of the managed host.
Affected Systems
The vulnerability exists in the open‑source Wazuh platform, versions 4.2.0 through 4.14.6 inclusive. The affected scripts are route‑null.c, netsh.c, pf.c, npf.c, ipfw.c, and disable‑account.c. These scripts run on both Linux and Windows hosts and are invoked when an active‑response rule triggers. If your environment uses any of those scripts in a version of Wazuh within the affected range, it is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 reflects a serious impact with moderate to high exploitation potential. The EPSS score is not available, but the attack requires only that an attacker can inject crafted events into Wazuh’s log inputs, such as a syslog source. Once injected, the malicious payload is executed immediately by a root‑privileged script. Because the vulnerability is not listed in the CISA KEV catalog, no publicly known exploit has yet been documented, yet the risk remains significant for environments exposed to untrusted log sources.
OpenCVE Enrichment