ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-25094”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-25094
Published
2020-12-17
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.