Wazuh是Wazuh开源的一个应用软件。用于收集,汇总,索引和分析安全数据,帮助组织检测入侵,威胁和行为异常。 Wazuh wazuh-agent和wazuh-manager 4.8.0之前的2.1.0版本存在代码注入漏洞,该漏洞源于多处Shell注入和不受信任的搜索路径,可能导致攻击者执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Wazuh | wazuh-agent | 2.1.0< 4.8.0 |
affected |
| Wazuh | wazuh-manager | 2.1.0< 4.8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Wazuh | wazuh-agent | 2.1.0 ~ 4.8.0 | - |
|
| Wazuh | wazuh-manager | 2.1.0 ~ 4.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-15617 | 6.5 MEDIUM | Wazuh GitHub Actions Workflow Exposure of Sensitive Credentials |
| CVE-2026-32983 | 5.8 MEDIUM | SSL/TLS Renegotiation DoS in Wazuh Manager authd service |
| CVE-2025-15615 | 5.8 MEDIUM | Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of S |
| CVE-2025-15612 | 4.8 MEDIUM | Wazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading |
| CVE-2026-32984 | 3.5 LOW | Heap buffer overflow in wazuh-authd |
| CVE-2023-7340 | 3.5 LOW | Wazuh authd service (os_auth) Heap-based Buffer Overflow |
No comments yet