CVE-2024-5721 is a missing authentication vulnerability in Logsign Unified SecOps Platform that can lead to remote code execution. The flaw exists in the implementation of the cluster HTTP API, which listens on TCP port 1924 when that component is enabled. Due to the absence of authentication checks before access to exposed functionality is granted, a remote attacker can reach privileged functionality without credentials and trigger arbitrary code execution. Successful exploitation results in code execution in the context of root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a standalone exploit set for Logsign Unified SecOps Platform vulnerabilities, centered on a Python proof-of-concept in exploit.py plus supporting Metasploit and Nuclei content. The main Python exploit chains CVE-2024-5716 and CVE-2024-5717: it triggers the forgot-password flow for a chosen user (default admin), brute-forces the 6-digit reset code using multiple threads, extracts the returned verification_code, resets the password, logs in, and then abuses the authenticated /api/settings/demo_mode endpoint to inject and execute attacker-controlled commands. The PoC supports direct command execution, a reverse-shell mode, and a default proof action that writes a file on the target. The repository also includes a Metasploit auxiliary module for the auth-bypass/reset issue only, a full Metasploit exploit module that delivers a Meterpreter session by wrapping the framework payload in a bash command and injecting it into demo_mode, and a Nuclei template that fingerprints potentially vulnerable Logsign instances by querying /api/settings/license_status and matching product/version strings. Overall, this is a real, operational network/web exploit repository targeting pre-authentication compromise of Logsign appliances, with clear offensive capability beyond mere detection.
This repository contains a single Metasploit module (modules/exploits/linux/http/logsign_exec.rb) that exploits a pre-authentication command injection vulnerability (CVE-2024-5721) in Logsign SIEM software. The exploit targets the '/api/log_browser/validate' HTTP endpoint, which is accessible without authentication and improperly handles user input, allowing arbitrary command execution as root. The module is weaponized, supporting customizable Python payloads (defaulting to a meterpreter reverse shell). It was tested against Logsign versions 4.4.2 and 4.4.137. The exploit is fully integrated into the Metasploit framework, making it easy to use and adapt. The main attack vector is network-based, requiring only HTTP(S) access to the vulnerable endpoint. No hardcoded IPs or domains are present; the endpoint is specified relative to the target's base URL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.