CVE-2020-25094: Logrhythm Platform Manager
Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.
Affected products
- Logrhythm Platform Manager: version 7.4.9 only
Published 2020-12-17. Last modified 2026-06-17.