HIGH
An issue was discovered in Logpoint before 7.5.0
Published Nov 7, 2024
7.5
HIGHCVSS 3.1
EPSS 0.33%
Description
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.
Affected products
No data.
-
- Version 0StatusaffectedConstraints<7.5.0
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest/ Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-43144 Advisory
- https://servicedesk.logpoint.com/hc/en-us/articles/21968264954525-Authentication-and-CSRF-bypass-leading-to-unauthorized-access Vendor Advisory
- https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security Product
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 7, 2024
Updated Nov 7, 2024
Reserved Oct 10, 2024
Link CVE-2024-48950
CISA Vulnrichment
Updated Nov 7, 2024
ENISA EUVD
EUVD-2024-43144 Assigner mitre
Published Nov 7, 2024
Updated Nov 7, 2024
Exploited since n/a
Link EUVD-2024-43144