Critical9.5
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

PT-2024-41: Bypass authentication in PT MaxPatrol SIEM, PT MaxPatrol VM, PT MaxPatrol EDR, PT MaxPatrol Carbon и PT MaxPatrol O2

Error type:

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Severity (CVSSv3.1): 9.0 (critical)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
  • Severity (CVSSv4.0): 9.5 (critical)

Description:

The vulnerability was identified in PT MaxPatrol SIEM, PT MaxPatrol VM, PT MaxPatrol EDR, PT MaxPatrol Carbon и PT MaxPatrol O2 that affects versions that include component PT MC version earlier than 101.4.8813 and component MPX version earlier than 27.2.14850.

The discovered vulnerability allows an attacker to bypass authentication. If successfully exploited, the attacker can impersonate any user and obtain all possible privileges.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 22.01.2025

Recommendations:

  • Update to version that includes Component PT MC version 101.4.8813 or later and Component MPX version 27.2.14850 or later.

Additional information:

Researcher: Lev Guryev (Wildberries)

Vendor:

Positive Technologies

Vulnerable product:

PT MaxPatrol SIEM, PT MaxPatrol VM, PT MaxPatrol EDR, PT MaxPatrol Carbon, PT MaxPatrol O2

Vulnerable versions:

Component PT MC version less than 101.4.8813 and component MPX version less than 27.2.14850