Vulnerabilities
15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-1044 | Critical Authentication Bypass in Logsign Unified SecOps Platform CVE-2025-1044 is a critical authentication bypass (CWE-287) in the web service of Logsign Unified SecOps Platform, the vendor's SIEM/SOAR offering. The web service listens on TCP port 443 by default, and because its authentication algorithm is improperly implemented, any remote attacker who can reach the service can bypass authentication without credentials. Successful exploitation grants unauthenticated access to the platform's web console, exposing stored security logs, alerts and configuration, and the 9.8 CVSS score reflects potentially high impact to confidentiality, integrity and availability. Any organization running Logsign Unified SecOps Platform is affected, with the greatest risk where the web interface is reachable from the internet or shared networks, a common pattern for analyst remote access and MSSP-hosted deployments. The flaw is not yet in CISA KEV and no public PoC is known, but EPSS assigns a 75.3% probability of exploitation within 30 days (99th percentile), so near-term exploitation attempts should be treated as likely. Do: Check the Logsign security advisory (referenced as ZDI-CAN-25336) for the patched release and upgrade promptly, since no fixed version numbers are included in the available data. Until patched, restrict TCP 443 access to the platform's web service to trusted management networks or VPN, confirm whether your instance is internet-facing, and review access and audit logs for signs of unauthenticated logins or configuration changes. | 9.8 | 75% |
| nicheon the order of a few thousand deployments, with an unknown smaller subset internet-exposed on TCP 443 | ||
| CVE-2024-5716 | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password reset mechanism. The issue results from the lack of restriction of excessive authentication attempts. An attacker can leverage this vulnerability to reset a user's password and bypass authentication on the system. Was ZDI-CAN-24164. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2024-7603 | Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. Logsign Unified SecOps Platform Directory Traversal Arbitrary Directory Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary directories on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete directories in the context of root. Was ZDI-CAN-25028. NVD description · AI analysis pending | 8.1 group max | 2% |
| — | ||
| CVE-2024-7564 | Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the get_response_json_result endpoint. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-CAN-24680. NVD description · AI analysis pending | 6.5 | 1% |
| — |