94 lines
2.8 KiB
JSON
Raw Normal View History

{
"id": "CVE-2023-42138",
"sourceIdentifier": "vultures@jpcert.or.jp",
"published": "2023-10-11T09:15:10.417",
"lastModified": "2023-10-18T19:57:05.243",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially crafted file."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de lectura fuera de l\u00edmites en KV STUDIO Ver. 11.62 y anteriores y KV REPLAY VIEWER Ver. 2.62 y anteriores. Si se explota esta vulnerabilidad, se puede divulgar informaci\u00f3n o se puede ejecutar c\u00f3digo arbitrario haciendo que un usuario de KV STUDIO PLAYER abra un archivo especialmente manipulado."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:keyence:kv_replay_viewer:*:*:*:*:*:*:*:*",
"versionEndExcluding": "2.63",
"matchCriteriaId": "F7533712-71AB-44CD-86F7-7F694FE353B9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:keyence:kv_studio:*:*:*:*:*:*:*:*",
"versionEndExcluding": "11.63",
"matchCriteriaId": "0BFABC3F-F01D-4B37-9D66-929A396D2E27"
}
]
}
]
}
],
"references": [
{
"url": "https://jvn.jp/en/vu/JVNVU94752076/index.html",
"source": "vultures@jpcert.or.jp",
"tags": [
"Third Party Advisory"
]
},
{
"url": "https://www.keyence.com/vulnerability231001",
"source": "vultures@jpcert.or.jp",
"tags": [
"Vendor Advisory"
]
}
]
}