CVE-2024-56084

HIGH

Logpoint Universal Normalizer < 5.7.0 - Authenticated Remote Code Execution via Universal Normalizer Creation

Title source: llm
STIX 2.1

Description

An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.

Scores

CVSS v3 7.1
EPSS 0.0032
EPSS Percentile 23.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
logpoint/universal_normalizer < 5.7.0
Published Dec 16, 2024
Tracked Since Feb 18, 2026