PT-2021-11775 · Unknown · Nxlog Community Edition
Published
2021-01-05
·
Updated
2022-04-29
·
CVE-2020-35488
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
NXLog Community Edition version 2.10.2150
Description:
The fileop module of the NXLog service allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration and the name of the directory created must use a Syslog field. For example, on Linux it is not possible to create a .. directory, and on Windows, it is not possible to create a CON directory.
Recommendations:
For NXLog Community Edition version 2.10.2150, consider disabling the fileop module of the NXLog service as a temporary workaround to prevent the denial of service attack until a patch is available. Restrict access to the Syslog service to minimize the risk of exploitation. Avoid using the Syslog field to create directories until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nxlog Community Edition