Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal.

This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
Published: 2026-09-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Data Exposure via Path Traversal
Action: Apply Patch
AI Analysis

Impact

The flaw is an improper limitation of pathname validation that allows an attacker to reference files outside the intended directory. By supplying a crafted file name, the attacker can read any file that the application process can access, potentially revealing configuration files, credential stores, or other sensitive data. The weakness is classified as CWE-22, indicating a classic path traversal issue that bypasses directory restrictions.

Affected Systems

The affected product is Innotim Software’s Logsign SIEM. Versions from 6.4.101 up to, but not including, 6.4.117 are vulnerable. Systems running any of these releases are at risk if the component that handles file paths is exposed to untrusted input.

Risk and Exploitability

The CVSS score of 7.1 places this vulnerability in the medium to high severity range. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been reported yet. The likely attack vector is submission of a crafted file name through an input that is interpreted as a path, such as a web interface or API endpoint. Successful exploitation would allow the attacker to read arbitrary files on the host, compromising confidentiality and possibly enabling further attacks.

Generated by OpenCVE AI on September 28, 2026 at 16:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Logsign SIEM to version 6.4.117 or later.
  • Configure the operating‑system file permissions so the application can access only the intended directory, thereby blocking traversal attempts.
  • Monitor application logs for abnormal file access patterns that might signal an attempted traversal attempt.

Generated by OpenCVE AI on September 28, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Innotim Software Telecommunications And Consulting Trade Ltd. Co.
Innotim Software Telecommunications And Consulting Trade Ltd. Co. logsign Siem
Vendors & Products Innotim Software Telecommunications And Consulting Trade Ltd. Co.
Innotim Software Telecommunications And Consulting Trade Ltd. Co. logsign Siem

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
Title Path Traversal in Innotim Software's Logsign SIEM
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Innotim Software Telecommunications And Consulting Trade Ltd. Co. Logsign Siem
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-28T16:32:27.875Z

Reserved: 2026-09-14T11:26:48.966Z

Link: CVE-2026-90925

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:25.238Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:21.863

Modified: 2026-09-28T17:17:52.437

Link: CVE-2026-90925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')