Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Product Security

Detection Gap in Alerting Pipeline for Null Search Interval Configurations

Avatar Kripa Thapa
June 15, 2026 11:10
Follow
Advisory ID GVD-2026-001
CVSSv 4.0 Vector AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSSv 4.0 Base Score 7.5
Severity
High
CVE
Pending
CWE
-
Date Published 2026-06-11
Description

In affected Guardsix SIEM versions, when an alert rule is created without an explicit search interval via the LPSM, Director API, SIEM API, or cloning vendor-supplied alerts, the alert rule configuration service assigns an incorrect default interval, causing affected rules to evaluate security events less frequently than intended, which may result in missed detections.

Affected Product

Logpoint v7.8.0, v7.8.1, v7.8.4, v7.9.0, and v7.9.1

Solution

Upgrade to Logpoint v7.8.5 or v7.9.3.

Acknowledgements
8Com
Remediation

Manually set an explicit search interval on all active alert rules created via LPSM, SIEM API, Director API or by cloning vendor alerts.

Additional resources

Customer self-service guide: scope, diagnosis, and remediation

Comments

Article is closed for comments.

Related articles

  • Guardsix Security Advisory: Response to Copy Fail and Dirty Frag Vulnerability
  • SSRF in ODBC Enrichment Source
  • Logpoint Agent (Standalone)
  • Incident subscriptions lost in LPSM when SIEM becomes temporarily unreachable
Was this article helpful? 0 out of 0 found this helpful
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.