logo

Getting Unauthenticated Remote Code Execution on the Logsign Unified SecOps Platform

ID: c083d622-7085-5222-947c-0184a3278c06

STIX ID: report--c083d622-7085-5222-947c-0184a3278c06

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
75/100

Date Published: 2024-07-01

Date Updated: 2026-05-01

Author: Yulin Sung

...
...

Trend Micro ZDI acquired reports of multiple vulnerabilities in the Logsign Unified SecOps Platform that allow attackers to bypass authentication (CVE-2024-5716) by abusing the password reset mechanism and, when chained with a second flaw, achieve remote unauthenticated code execution via HTTP; the advisory describes the affected Python-based web server, API exposure, and the risk posed to deployments of Logsign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.