PT-2024-11776 · Logpoint · Logpoint

Timo Fahlenbock

·

Published

2024-04-27

·

Updated

2024-07-03

·

CVE-2022-48685

CVSS v3.1

7.7

High

VectorAC:L/AV:L/A:H/C:H/I:H/PR:H/S:C/UI:R
Name of the Vulnerable Software and Affected Versions Logpoint versions 7.1 through 7.1.1 Logpoint version 7.1.2 is not affected, so the range can be simplified to versions prior to 7.1.2.
Description An issue was discovered in Logpoint where the daily executed cron file clean secbi old logs is writable by all users and is executed as root, leading to privilege escalation.
Recommendations For Logpoint versions prior to 7.1.2, update to version 7.1.2 or later to resolve the issue. As a temporary workaround, consider changing the permissions of the clean secbi old logs cron file to prevent it from being writable by all users until a patch is applied.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2022-48685

Affected Products

Logpoint