9.8
CVSSv3

CVE-2025-1044

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00645 | KEV: Not Included
Published: 11/02/2025 Updated: 11/02/2025

Vulnerability Summary

Unauthenticated Authentication Bypass in Logsign Unified SecOps Platform

A critical authentication bypass vulnerability exists in the Logsign Unified SecOps Platform, which allows remote attackers to circumvent authentication mechanisms without requiring any prior credentials. The vulnerability specifically resides within the web service running on the default TCP port 443 and stems from inadequate implementation of the authentication algorithm. An attacker can exploit this flaw to gain unauthorized access to the system. The vulnerability was identified as ZDI-CAN-25336 and poses significant security risks by enabling unauthenticated remote access to the platform.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

logsign unified secops platform