CVE-2022-24038: Unauthorized modification in Karmasis Informatics Infraskope SIEM+
Published Nov 18, 2022
·Updated
Karmasis Informatics Infraskope SIEM+
has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.
Affected Software
2 affected components
Karmasis Infraskope Security Event Manager<7.10.00
Karmasis Infraskope Siem\+<7.10.00
Remediation
Information
Update the Karmasis Informatics Infraskope SIEM+ software to >= 7.10.xx.
Event History
Nov 18, 2022
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-24038?
CVE-2022-24038 is a vulnerability in Karmasis Informatics Infraskope SIEM+ that allows an unauthenticated attacker to damage the page where the agents are listed.
2
How severe is CVE-2022-24038?
CVE-2022-24038 has a severity level of 6.5, which is classified as high.
3
What software is affected by CVE-2022-24038?
The affected software is Karmasis Infraskope Security Event Manager version up to 7.10.00.
4
Is authentication required to exploit CVE-2022-24038?
No, authentication is not required to exploit CVE-2022-24038.
5
How can I fix CVE-2022-24038?
To fix CVE-2022-24038, update Karmasis Infraskope Security Event Manager to a version higher than 7.10.00.