Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r929-7jrv-6rh2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.

LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.

EPSS

Процентиль: 94%
0.12431
Средний

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.

EPSS

Процентиль: 94%
0.12431
Средний

Дефекты

CWE-74