{ "id": "CVE-2022-48474", "sourceIdentifier": "cve-coordination@incibe.es", "published": "2023-09-12T08:15:13.473", "lastModified": "2024-11-21T07:33:24.310", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, causing a memory failure error that shuts down the process." }, { "lang": "es", "value": "Control de Ciber, en su versi\u00f3n 1.650, se ve afectado por una condici\u00f3n de Denegaci\u00f3n de Servicio a trav\u00e9s de la funci\u00f3n \"version\". El env\u00edo de una solicitud maliciosa podr\u00eda hacer que el servidor compruebe si un componente no reconocido est\u00e1 actualizado, lo que provocar\u00eda un error de memoria que cerrar\u00eda el proceso." } ], "metrics": { "cvssMetricV31": [ { "source": "cve-coordination@incibe.es", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "baseScore": 8.2, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 4.2 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 3.6 } ] }, "weaknesses": [ { "source": "cve-coordination@incibe.es", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-400" } ] }, { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-400" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:cbm:control_de_ciber:1.650:*:*:*:*:*:*:*", "matchCriteriaId": "AB599A8B-64BE-486E-B426-9573F91B2AC5" } ] } ] } ], "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-control-de-ciber", "source": "cve-coordination@incibe.es", "tags": [ "Third Party Advisory" ] }, { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-control-de-ciber", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ] } ] }