VYPR
Critical severity9.8NVD Advisory· Published Dec 17, 2020· Updated Jun 17, 2026

CVE-2020-25094

CVE-2020-25094

Description

LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:logrhythm:platform_manager:7.4.9:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:logrhythm:platform_manager:7.4.9:*:*:*:*:*:*:*
    • (no CPE)range: =7.4.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.