CVE Feed

    Dashboard / CVE / CVE-2020-35488

    CVE-2020-35488

    The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory created must use a Syslog field. (For example, on Linux it is not possible to create a .. directory. On Windows, it is not possible to create a CON directory.)

    Published:Jan 5, 2021
    Last Modified:Nov 21, 2024
    EPS:Jan 5, 2021
    EPSS Score:0.10816
    CVSS Score:7.5

    Affected Products

    Vendor
    Nxlog
    Product
    Nxlog

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High