CVE-2022-24036: Unauthorized modification in Karmasis Informatics Infraskope SIEM+
Published Nov 16, 2022
·Updated
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.
Affected Software
2 affected components
Karmasis Infraskope Security Event Manager<7.10.00
Karmasis Infraskope Siem\+<7.10.00
Remediation
Information
Update the Karmasis Informatics Infraskope SIEM+ software to >= 7.10.xx.
Event History
Nov 16, 2022
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-24036?
CVE-2022-24036 is a vulnerability found in Karmasis Informatics Infraskope SIEM+ that allows an unauthenticated attacker to modify logs.
2
What is the severity of CVE-2022-24036?
CVE-2022-24036 has a severity level of 8.6 (high).
3
How does CVE-2022-24036 affect Karmasis Informatics Infraskope SIEM+?
CVE-2022-24036 affects the unauthenticated access vulnerability in Karmasis Informatics Infraskope SIEM+, allowing an attacker to modify logs without authentication.
4
What software versions are affected by CVE-2022-24036?
Karmasis Informatics Infraskope Security Event Manager versions up to and excluding 7.10.00 are affected by CVE-2022-24036.
5
How can I fix CVE-2022-24036?
To fix CVE-2022-24036, it is recommended to update Karmasis Informatics Infraskope SIEM+ to version 7.10.00 or later.