An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.
References
Configurations
History
18 Apr 2025, 13:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest/ - Release Notes | |
References | () https://servicedesk.logpoint.com/hc/en-us/articles/21968264954525-Authentication-and-CSRF-bypass-leading-to-unauthorized-access - Vendor Advisory | |
References | () https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-Security - Product | |
First Time |
Logpoint
Logpoint siem |
|
CPE | cpe:2.3:a:logpoint:siem:*:*:*:*:*:*:*:* |
Information
Published : 2024-11-07 17:15
Updated : 2025-04-18 13:12
NVD link : CVE-2024-48950
Mitre link : CVE-2024-48950
CVE.ORG link : CVE-2024-48950
JSON object : View
Products Affected
logpoint
- siem
CWE
CWE-306
Missing Authentication for Critical Function