ZeroHour

CVE-2025-1044

niche

Critical Authentication Bypass in Logsign Unified SecOps Platform

CVSS 3.1
9.8 critical
EPSS
75%p99
Published
()
Modified
AI analysis

CVE-2025-1044 is a critical authentication bypass (CWE-287) in the web service of Logsign Unified SecOps Platform, the vendor's SIEM/SOAR offering. The web service listens on TCP port 443 by default, and because its authentication algorithm is improperly implemented, any remote attacker who can reach the service can bypass authentication without credentials. Successful exploitation grants unauthenticated access to the platform's web console, exposing stored security logs, alerts and configuration, and the 9.8 CVSS score reflects potentially high impact to confidentiality, integrity and availability. Any organization running Logsign Unified SecOps Platform is affected, with the greatest risk where the web interface is reachable from the internet or shared networks, a common pattern for analyst remote access and MSSP-hosted deployments. The flaw is not yet in CISA KEV and no public PoC is known, but EPSS assigns a 75.3% probability of exploitation within 30 days (99th percentile), so near-term exploitation attempts should be treated as likely.

What to do: Check the Logsign security advisory (referenced as ZDI-CAN-25336) for the patched release and upgrade promptly, since no fixed version numbers are included in the available data. Until patched, restrict TCP 443 access to the platform's web service to trusted management networks or VPN, confirm whether your instance is internet-facing, and review access and audit logs for signs of unauthenticated logins or configuration changes.

Affected
logsign unified secops platform
Estimated exposure
nicheon the order of a few thousand deployments, with an unknown smaller subset internet-exposed on TCP 443 — No public install counts or scan data were available, so the estimate rests on Logsign's profile as a regionally concentrated SIEM/SOAR vendor whose platform is typically deployed once per organization, of which only some instances expose…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.

Vendors
logsign
Products
unified secops platform
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.