CVE-2020-25096 Information

Description

LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges intended to limit what data and services they can interact with. However no access control is enforced for WebSocket-based communication to the PM application server which will forward requests to any configured back-end server regardless of whether the user’s access rights should permit this. As a result even the most low-privileged user can interact with any back-end component that has a LogRhythm agent installed.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://cybercx.com.au/blog/2020/12/15/logrhythm-zero-days/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: