Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.
History

Tue, 18 Feb 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Logsign
Logsign unified Secops Platform
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:logsign:unified_secops_platform:*:*:*:*:*:*:*:*
Vendors & Products Logsign
Logsign unified Secops Platform
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 12 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 20:00:00 +0000

Type Values Removed Values Added
Description Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 443 by default. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25336.
Title Logsign Unified SecOps Platform Authentication Bypass Vulnerability
Weaknesses CWE-287
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2025-02-12T14:32:55.170Z

Reserved: 2025-02-04T21:00:30.180Z

Link: CVE-2025-1044

cve-icon Vulnrichment

Updated: 2025-02-12T14:30:06.656Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-11T20:15:35.913

Modified: 2025-02-18T21:34:01.863

Link: CVE-2025-1044

cve-icon Redhat

No data.