First published: Fri Nov 18 2022(Updated: )
Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.
Credit: cve@usom.gov.tr iletisim@usom.gov.tr
Affected Software | Affected Version | How to fix |
---|---|---|
Karmasis Infraskope Siem+ | <7.10.00 | |
Karmasis Infraskope Security Event Manager | <7.10.00 |
Update the Karmasis Informatics Infraskope SIEM+ software to >= 7.10.xx.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24038 is a vulnerability in Karmasis Informatics Infraskope SIEM+ that allows an unauthenticated attacker to damage the page where the agents are listed.
CVE-2022-24038 has a severity level of 6.5, which is classified as high.
The affected software is Karmasis Infraskope Security Event Manager version up to 7.10.00.
No, authentication is not required to exploit CVE-2022-24038.
To fix CVE-2022-24038, update Karmasis Infraskope Security Event Manager to a version higher than 7.10.00.