CVE-2024-7604 is an authentication bypass vulnerability in the Logsign Unified SecOps Platform, allowing local attackers to bypass authentication via the HTTP API service. This high-severity flaw (CVSS 7.8) stems from improper validation of the user's license expiration date, enabling unauthorized access with high impact on confidentiality, integrity, and availability. While authentication is required to exploit, the attack complexity is low. There is currently no public exploit intelligence, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.4.20CPE matchmatch criteria | cpe:2.3:a:logsign:unified_secops_platform:6.4.20:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.