Impact
A flaw in rsyslog’s imdtls input module allows a remote attacker to bypass permitted‑peer identity checks after a successful DTLS handshake. If the attacker presents a certificate signed by a certificate authority trusted by the rsyslog listener, the verified peer identity is not checked and the attacker may inject arbitrary syslog messages into the input stream. The weakness is an authentication failure (CWE‑287) that enables unauthorized data injection and can lead to tampered logs, stealthy operations, or data exfiltration.
Affected Systems
The vulnerability affects installations of rsyslog that use the imdtls input module configured for name or fingerprint authentication. No specific product versions are listed, but any rsyslog deployment that enables this configuration is potentially impacted.
Risk and Exploitability
The CVSS score of 3.1 indicates low base severity, and the EPSS score is unavailable. The flaw is not yet listed in the CISA KEV catalog, suggesting limited evidence of exploitation. Nonetheless, the attack vector is remote over a network connection that uses DTLS, and the attacker must have a valid certificate from a trusted CA. The risk is that authenticated peers are effectively ignored, granting an attacker the ability to inject unauthorized logs into the system.
OpenCVE Enrichment