Executive brief
A security flaw was found in guardsix (formerly Logpoint) security software, specifically within its database connection plugins. The system incorrectly reused sensitive login credentials even when a user changed the destination server, allowing an authorized operator to redirect those credentials to a different, unauthorized internal system. This could lead to the exposure of internal database information or unauthorized access to other parts of the corporate network.
Technical details
A logic flaw exists in the guardsix (formerly Logpoint) ODBC Enrichment Plugins due to improper handling of credential state during configuration updates. When an authenticated 'Operator' user modifies an existing Enrichment Source's connection parameters (Host, IP, or Port), the system fails to clear the previously stored credentials. This allows an attacker to perform a Server-Side Request Forgery (SSRF) by redirecting the connection to an arbitrary internal endpoint, where the stored credentials are then automatically transmitted. The vulnerability is tracked as CWE-918 and is resolved in ODBC Enrichment Plugin version 5.2.1 and Logpoint version 7.9.0.0.
Affected products
- guardsix ODBC Enrichment Plugins before 5.2.1
- guardsix Logpoint (guardsix) before 7.9.0.0
Timeline
- 2026-04-22: advisory: Initial advisory published by guardsix and MITRE
- 2026-04-22: disclosed
- 2026-05-12: other: NVD analysis and CPE information added