CVE-2020-25094

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
17/12/2020
Last modified:
21/07/2021

Description

LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:logrhythm:platform_manager:7.4.9:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools