Description
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.

This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.
Published: 2026-08-17
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Logsign SIEM application contains an Insufficiently Protected Credentials flaw (CWE‑522) that permits an attacker to retrieve embedded sensitive data. The vulnerability is triggered when credentials are inadequately safeguarded, allowing a malicious actor to access confidential information stored in the system. A successful exploitation would expose private logs, configuration details, or authentication secrets, compromising confidentiality and possibly giving the attacker further privileges.

Affected Systems

The affected product is Logsign SIEM from Innotim Software Telecommunications and Consulting Trade Ltd. Co. Versions 6.4.97 through 6.4.113 are vulnerable. Any installation running these releases without the latest update (version 6.4.114 or newer) is at risk.

Risk and Exploitability

The CVSS score of 9 indicates high severity, but the EPSS score is not available and the issue is not listed in CISA KEV, suggesting no widespread exploitation has been observed yet. Attackers could exploit the flaw over the network by authenticating with a compromised or weak credential that is stored or transmitted insecurely. Since the vulnerability permits direct data read, it carries a significant confidentiality impact and could serve as a foothold for further compromise.

Generated by OpenCVE AI on August 17, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Logsign SIEM to version 6.4.114 or later, which contains the fix for the credentials protection flaw.
  • Restrict access to the management interfaces using least‑privilege accounts and enforce strong, unique passwords to prevent credential theft.
  • Review and harden credential storage, ensuring that any embedded credentials are encrypted or removed from configuration files.
  • Monitor system logs for unusual read operations or authentication attempts to detect unauthorized data retrieval.

Generated by OpenCVE AI on August 17, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Innotim Software Telecommunications And Consulting Trade Ltd. Co.
Innotim Software Telecommunications And Consulting Trade Ltd. Co. logsign Siem
Vendors & Products Innotim Software Telecommunications And Consulting Trade Ltd. Co.
Innotim Software Telecommunications And Consulting Trade Ltd. Co. logsign Siem

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.
Title Sensitive Data Exposure in Innotim Software's Logsign SIEM
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Innotim Software Telecommunications And Consulting Trade Ltd. Co. Logsign Siem
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-17T14:47:16.460Z

Reserved: 2026-07-03T10:03:47.380Z

Link: CVE-2026-14564

cve-icon Vulnrichment

Updated: 2026-08-17T14:47:12.461Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T13:16:50.797

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-14564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:40:22Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials