Description
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data.

This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.
Published: 2026-08-17
Score: 9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Logsign SIEM application contains an Insufficiently Protected Credentials flaw (CWE‑522) that permits an attacker to retrieve embedded sensitive data. The vulnerability is triggered when credentials are inadequately safeguarded, allowing a malicious actor to access confidential information stored in the system. A successful exploitation would expose private logs, configuration details, or authentication secrets, compromising confidentiality and possibly giving the attacker further privileges.

Affected Systems

The affected product is Logsign SIEM from Innotim Software Telecommunications and Consulting Trade Ltd. Co. Versions 6.4.97 through 6.4.113 are vulnerable. Any installation running these releases without the latest update (version 6.4.114 or newer) is at risk.

Risk and Exploitability

The CVSS score of 9 indicates high severity, but the EPSS score is not available and the issue is not listed in CISA KEV, suggesting no widespread exploitation has been observed yet. Attackers could exploit the flaw over the network by authenticating with a compromised or weak credential that is stored or transmitted insecurely. Since the vulnerability permits direct data read, it carries a significant confidentiality impact and could serve as a foothold for further compromise.

Generated by OpenCVE AI on August 17, 2026 at 13:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Logsign SIEM to version 6.4.114 or later, which contains the fix for the credentials protection flaw.
  • Restrict access to the management interfaces using least‑privilege accounts and enforce strong, unique passwords to prevent credential theft.
  • Review and harden credential storage, ensuring that any embedded credentials are encrypted or removed from configuration files.
  • Monitor system logs for unusual read operations or authentication attempts to detect unauthorized data retrieval.

Generated by OpenCVE AI on August 17, 2026 at 13:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.
Title Sensitive Data Exposure in Innotim Software's Logsign SIEM
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-17T14:47:16.460Z

Reserved: 2026-07-03T10:03:47.380Z

Link: CVE-2026-14564

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T13:16:50.797

Modified: 2026-08-17T13:16:50.797

Link: CVE-2026-14564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T13:30:07Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials