PT-2024-39516 · Logsign · Logsign Unified Secops Platform

Abdessamad Lahlali

+1

·

Published

2024-09-26

·

Updated

2025-01-03

·

CVE-2024-9257

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Logsign Unified SecOps Platform (affected versions not specified)
Description This issue allows remote attackers to delete arbitrary files within sensitive directories on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this issue. The specific flaw exists within the "delete gsuite key file" endpoint, resulting from the lack of proper validation of a user-supplied filename prior to using it in file operations. An attacker can leverage this issue to delete critical files on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-9257
ZDI-24-1295

Affected Products

Logsign Unified Secops Platform