Impact
The flaw is an improper limitation of pathname validation that allows an attacker to reference files outside the intended directory. By supplying a crafted file name, the attacker can read any file that the application process can access, potentially revealing configuration files, credential stores, or other sensitive data. The weakness is classified as CWE-22, indicating a classic path traversal issue that bypasses directory restrictions.
Affected Systems
The affected product is Innotim Software’s Logsign SIEM. Versions from 6.4.101 up to, but not including, 6.4.117 are vulnerable. Systems running any of these releases are at risk if the component that handles file paths is exposed to untrusted input.
Risk and Exploitability
The CVSS score of 7.1 places this vulnerability in the medium to high severity range. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been reported yet. The likely attack vector is submission of a crafted file name through an input that is interpreted as a path, such as a web interface or API endpoint. Successful exploitation would allow the attacker to read arbitrary files on the host, compromising confidentiality and possibly enabling further attacks.
OpenCVE Enrichment