CVE-2025-1044
nicheCritical Authentication Bypass in Logsign Unified SecOps Platform
CVE-2025-1044 is a critical authentication bypass (CWE-287) in the web service of Logsign Unified SecOps Platform, the vendor's SIEM/SOAR offering. The web service listens on TCP port 443 by default, and because its authentication algorithm is improperly implemented, any remote attacker who can reach the service can bypass authentication without credentials. Successful exploitation grants unauthenticated access to the platform's web console, exposing stored security logs, alerts and configuration, and the 9.8 CVSS score reflects potentially high impact to confidentiality, integrity and availability. Any organization running Logsign Unified SecOps Platform is affected, with the greatest risk where the web interface is reachable from the internet or shared networks, a common pattern for analyst remote access and MSSP-hosted deployments. The flaw is not yet in CISA KEV and no public PoC is known, but EPSS assigns a 75.3% probability of exploitation within 30 days (99th percentile), so near-term exploitation attempts should be treated as likely.
What to do: Check the Logsign security advisory (referenced as ZDI-CAN-25336) for the patched release and upgrade promptly, since no fixed version numbers are included in the available data. Until patched, restrict TCP 443 access to the platform's web service to trusted management networks or VPN, confirm whether your instance is internet-facing, and review access and audit logs for signs of unauthenticated logins or configuration changes.
| logsign unified secops platform | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.
- Vendors
- logsign
- Products
- unified secops platform
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.