LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cybercx.com.au/blog/2020/12/15/logrhythm-zero-days/ |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2020-12-17T02:04:12
Updated: 2024-08-04T15:26:09.702Z
Reserved: 2020-09-03T00:00:00
Link: CVE-2020-25094

No data.

Status : Modified
Published: 2020-12-17T03:15:13.127
Modified: 2024-11-21T05:17:19.147
Link: CVE-2020-25094

No data.