TROYANOSYVIRUS
Volver a CVEs

CVE-2024-48952

MEDIUM
6.4

Descripcion

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.

Detalles CVE

Puntuacion CVSS v3.16.4
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
Vector de ataqueADJACENT_NETWORK
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado11/7/2024
Ultima modificacion4/30/2025
Fuentenvd
Avistamientos honeypot0

This product uses data from the NVD API but is not endorsed or certified by the NVD.