Logrhythm Platform Manager vulnerabilities
3 known vulnerabilities affecting logrhythm/platform_manager.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2020-25094P2CRITICALCVSS 9.8v7.4.92020-12-17
CVE-2020-25094 [CRITICAL] CWE-78 CVE-2020-25094: LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject a
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.
nvd
CVE-2020-25096P3HIGHCVSS 8.8v7.4.92020-12-17
CVE-2020-25096 [HIGH] CVE-2020-25096: LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be de
LogRhythm Platform Manager (PM) 7.4.9 has Incorrect Access Control. Users within LogRhythm can be delegated different roles and privileges, intended to limit what data and services they can interact with. However, no access control is enforced for WebSocket-based communication to the PM application server, which will forward requests to any configured back-en
nvd
CVE-2020-25095P3HIGHCVSS 8.8v7.4.92020-12-17
CVE-2020-25095 [HIGH] CWE-352 CVE-2020-25095: LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site Web
LogRhythm Platform Manager (PM) 7.4.9 allows CSRF. The Web interface is vulnerable to Cross-site WebSocket Hijacking (CSWH). If a logged-in PM user visits a malicious site in the same browser session, that site can perform a CSRF attack to create a WebSocket from the victim client to the vulnerable PM server. Once the socket is created, the malicious
nvd