Impact
The FortiGate key‑value syslog parser in Graylog mishandles quoted values containing equals signs or escaped quotes, allowing embedded keys to overwrite or remove top‑level fields such as srcip, dstip, date, time, and tz. An attacker who can send arbitrary syslog messages can therefore modify or delete critical log fields, making it possible to conceal malicious activity and evade log‑based detection. This represents a log‑tampering flaw that can compromise the integrity and completeness of security data.
Affected Systems
Packets are affected on Graylog Server versions prior to 6.3.12, 7.0.7 and 7.1.2, as well as on the Graylog Forwarder before 7.3. The affected product is Graylog Server (formerly Graylog2) and the associated Forwarder component, both provided by the vendor Graylog2.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity, but no EPSS score is available; the vulnerability is not listed in the CISA KEV catalog. Because no authentication is required and an unauthenticated network sender can craft syslog payloads, the attack vector is likely a remote network submission to the syslog listening port. If exploited, the attacker could alter the log stream to delete or overwrite fields, thereby altering the perceived source or destination of traffic and masking malicious events.
OpenCVE Enrichment
Github GHSA