CVE-2024-56084

An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:logpoint:universal_normalizer:*:*:*:*:*:*:*:*

History

20 Jun 2025, 18:47

Type Values Removed Values Added
References () https://servicedesk.logpoint.com/hc/en-us/articles/22137632418845-Remote-Code-Execution-while-creating-Universal-Normalizer - () https://servicedesk.logpoint.com/hc/en-us/articles/22137632418845-Remote-Code-Execution-while-creating-Universal-Normalizer - Vendor Advisory
First Time Logpoint
Logpoint universal Normalizer
CPE cpe:2.3:a:logpoint:universal_normalizer:*:*:*:*:*:*:*:*

23 Dec 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-16 06:15

Updated : 2025-06-20 18:47


NVD link : CVE-2024-56084

Mitre link : CVE-2024-56084

CVE.ORG link : CVE-2024-56084


JSON object : View

Products Affected

logpoint

  • universal_normalizer
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')