Impact
An input validation flaw in Logsign SIEM allows arbitrary code injection, granting attackers the ability to execute commands on the underlying host. This flaw enables compromise of confidentiality, integrity, and availability of the affected system and aligns with CWE‑94, Improper Control of Generation of Code.
Affected Systems
Logsign SIEM versions from 6.4.101 up to but not including 6.4.117 are impacted. The product is distributed by Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Users of these specific releases must assess whether they are running any vulnerable version.
Risk and Exploitability
The CVSS score of 8.8 marks it as a high‑severity risk. EPSS data are unavailable, and the lack of KEV listing does not eliminate the threat. Based on the description, it is inferred that attackers could deliver malicious payloads remotely through the Logsign SIEM application interface, representing the likely attack vector for code injection.
OpenCVE Enrichment