Impact
The vulnerability in Logsign SIEM is an improper control of code generation, allowing an attacker to inject and execute arbitrary code without authentication. This code injection flaw, identified as CWE‑94, gives a remote attacker the ability to run any commands with the privileges of the SIEM process, compromising confidentiality, integrity, and availability of the entire SIEM deployment. The flaw affects all versions prior to 6.4.115.
Affected Systems
The affected product is Innotim Software's Logsign SIEM, specifically all releases before version 6.4.115. Users running older builds should identify their version and plan remediation.
Risk and Exploitability
With a CVSS base score of 9.8 the flaw is considered critical. The EPSS score of less than 1% indicates low current exploitation probability, and the lack of a KEV listing does not reduce the potential impact. Based on the description, it is inferred that an unauthenticated attacker can reach the vulnerable interface, likely via exposed management ports or web endpoints, and execute code directly on the host. Attackers need only network access to the SIEM and no specific user credential. Once exploited, arbitrary commands can be run or persistence installed.
OpenCVE Enrichment