CVE-2024-5721
HIGHLogsign Unified SecOps Platform 6.4.6-6.4.8 - Unauthenticated Remote Code Execution via Cluster HTTP API
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-5721.
PoCs published by byjanke, Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/logsign_exec.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2024-5716 (authentication bypass) and CVE-2024-5717 (command injection) in Logsign Unified SecOps Platform. The exploit chains these vulnerabilities to achieve unauthenticated remote code execution.
Description
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the cluster HTTP API, which listens on TCP port 1924 when enabled. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24169.
Exploits (2)
This repository contains functional exploit code for CVE-2024-5716 (authentication bypass) and CVE-2024-5717 (command injection) in Logsign Unified SecOps Platform. The exploit chains these vulnerabilities to achieve unauthenticated remote code execution.
This Metasploit module exploits a command injection vulnerability in Logsign's API endpoint, allowing unauthenticated remote code execution as root. The exploit crafts a malicious JSON payload to inject a Python reverse shell via the 'file' parameter.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H