CVE-2020-25094

CVE-2020-25094

LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.

Source: CVE-2020-25094

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다