<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Elastic Beats</title>
  <link>https://cvedaily.com/pages/tags/beats.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/beats.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Elastic Beats</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2025-41739 – An unauthenticated remote attacker, who beats a race condition, can exploit a fl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41739</guid>
    <pubDate>Mon, 01 Dec 2025 10:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41739</strong></p>
  <p>An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49379 – In the Linux kernel, the following vulnerability has been resolved:

driver core...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49379</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49379</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  driver core: Fix wait_for_device_probe() & deferred_probe_timeout interaction  Mounting NFS rootfs was timing out when deferred_probe_timeout was non-zero [1].  This was because ip_auto_config() initcall times out waiting for the network interfaces to show up when deferred_probe_timeout was non-zero. While ip_auto_config() calls…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27867 – An authentication issue was addressed with improved state management. This issue...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27867</guid>
    <pubDate>Wed, 26 Jun 2024 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27867</strong></p>
  <p>An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A326, AirPods Firmware Update 6F8, and Beats Firmware Update 6F8. When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-49922 – An issue was discovered by Elastic whereby Beats and Elastic Agent would log a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49922</guid>
    <pubDate>Tue, 12 Dec 2023 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-49922</strong></p>
  <p>An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Beats or Elastic Agent attempted to ingest, this could lead to the insertion of sensitive or private information in the Beats or…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-31421 – It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31421</guid>
    <pubDate>Thu, 26 Oct 2023 04:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-31421</strong></p>
  <p>It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the client is configured to connect to an IP address (instead of a hostname) it does not validate the server certificate's IP SAN…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-7620 – Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7620</guid>
    <pubDate>Wed, 30 Oct 2019 14:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-7620</strong></p>
  <p>Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to connect to the port the Logstash beats input could send a specially crafted network packet that would cause Logstash to stop responding.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-7665 – An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious fil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-7665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-7665</guid>
    <pubDate>Mon, 05 Mar 2018 07:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-7665</strong></p>
  <p>An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.php, or the coverPhoto parameter to edit_account.php.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-7665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2537 – Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and earlier, (b) Be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2537</guid>
    <pubDate>Mon, 22 May 2006 23:10:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2537</strong></p>
  <p>Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and earlier, (b) Beats of Rage (BOR) 1.0029 and earlier, and (c) Horizontal Shooter BOR (HOR) 2.0000 and earlier allow remote attackers to execute code via format string specifiers in configurations used in various mod files, as demonstrated by the (1) music identifier in data/scenes/intro.txt, which is not properly handled in the updat…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2537">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
