Impact
The flaw allows an attacker to log in to Logsign SIEM with default credentials. This provides them with administrative access to the SIEM system, potentially allowing them to view all logs, manage configurations, and exercise full control over the security monitoring environment. The impact is equivalent to that of a privileged user within the SIEM.
Affected Systems
Innotim Software’s Logsign SIEM, versions 6.4.101 through 6.4.116, distributed by Innotim Software, Telecommunications and Consultancy Trade Ltd. Co., is vulnerable due to the presence of default administrative credentials set during installation or upgrade to these releases.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical, indicating remote privileged access. The EPSS score is not available, and the lack of a KEV listing does not reduce the risk. The likely attack vector is through the SIEM’s web or API login interface, where an attacker can reuse hard‑coded or common default usernames and passwords with no further exploitation steps required.
OpenCVE Enrichment