Impact
Ech0 applications before version 4.4.3 do not enforce administrator rights on dashboard log endpoints. Any authenticated user can send a GET request to /api/system/logs and subscribe to server‑sent events and WebSocket streams. The payload of these endpoints includes file paths, stack traces, and internal URLs, giving an attacker the ability to read sensitive operational data and potentially analyze the system for further attacks.
Affected Systems
The vulnerability affects the Ech0 product from the vendor lin‑snow. All installations using a version earlier than 4.4.3 are vulnerable; no specific patch version is listed as affected beyond this cutoff.
Risk and Exploitability
The CVSS score of 7.1 indicates a high–moderate severity, while the EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers must first obtain valid authentication, but any authenticated user can use the exposed endpoints, making exploitation straightforward once a session is available. Consequently, this flaw poses a significant confidentiality risk to organizations running Ech0 before 4.4.3.
OpenCVE Enrichment