Vulnerability Description
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Logpoint | Soar | < 7.5.0 |
Related Weaknesses (CWE)
References
- https://docs.logpoint.com/docs/whats-new-in-logpoint/en/latest/Release Notes
- https://servicedesk.logpoint.com/hc/en-us/articles/21968950913693-Static-JWT-KeyVendor Advisory
- https://servicedesk.logpoint.com/hc/en-us/sections/7201103730845-Product-SecuritProduct
FAQ
What is CVE-2024-48952?
CVE-2024-48952 is a vulnerability with a CVSS score of 6.4 (MEDIUM). An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability ena...
How severe is CVE-2024-48952?
CVE-2024-48952 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48952?
Check the references section above for vendor advisories and patch information. Affected products include: Logpoint Soar.