mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-09-17 18:45:49 +00:00
403 lines
16 KiB
JSON
403 lines
16 KiB
JSON
{
|
|
"id": "CVE-2012-4356",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2012-08-19T20:55:01.863",
|
|
"lastModified": "2024-11-21T01:42:44.557",
|
|
"vulnStatus": "Modified",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allow remote attackers to read arbitrary files via port-46824 TCP packets specifying a file-open operation with opcode 0x78 and a .. (dot dot) in a pathname, followed by a file-read operation with opcode (1) 0x96, (2) 0x97, or (3) 0x98."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "M\u00faltiples vulnerabilidades de salto de directorio en Sielco Sistemi Winlog Pro SCADA antes de v2.07.17 y Winlog Lite SCADA antes de v2.07.17 permiten a atacantes remotos leer archivos de su elecci\u00f3n a trav\u00e9s de un paquete al puerto TCP 46824 especificando una operaci\u00f3n de apertura de archivo con c\u00f3digo de operaci\u00f3n 0x78 y un .. (punto punto) en una ruta de acceso, seguida de una operaci\u00f3n de lectura de archivo con c\u00f3digo de operaci\u00f3n (1) 0x96, (2) 0x97 o (3) 0x98."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"baseScore": 4.3,
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "MEDIUM",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE"
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 8.6,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-22"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:*:*:*:*:*:*:*:*",
|
|
"versionEndIncluding": "2.07.16",
|
|
"matchCriteriaId": "C8B4BB2C-EB82-456E-A9CA-72D6C862ECC6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.00:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8FF1B03C-54CF-4027-A58B-DFCE4FBA84CC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.03:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0D672AD8-9A7D-4257-8D1B-A79051F7EF49"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.04:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2D2041DF-7469-4B19-9C58-A776EC09883A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.06:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "EEE7A9FD-CFFF-4D15-9BB0-014984BF390D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.09:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CD4B97C6-1A3C-4D9F-ADD5-EE4D2B3FE6B6"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0DBFE030-8A5F-478F-8BB0-1FF60C9A49FE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.12:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "16C51DFE-73CA-4961-BC26-F0E285A4AE1B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.13:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "924BCED2-A2C9-4A7B-9291-C9D1725A23C0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.14:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9728479C-278D-4E07-8597-DB32223A4E2C"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.18:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A146B9C7-2742-4ED7-BB9B-C5C91C23AA04"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.21:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6F570F84-49C0-44F2-AE08-E5ACC40FDDEE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.24:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3EBD17A7-8F08-4ECA-B577-3D120B5B72FA"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.25:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5ABEFD13-6D5D-4617-B117-01A8DA34C4FC"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.28:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2A22ED36-2B1A-4D04-86DB-E4CE0EB85DA9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.40:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9A3B466B-01FA-4D22-B0B0-A2ABBB748BB3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.46:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1AD7295A-26E9-477B-86C1-8260A1849356"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.50:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E44368E8-F333-41DF-A210-F03A82436A87"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.60:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "FA2674A1-474A-4976-AE2D-ADEEBED8BB38"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.73:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "4C0D5188-AEA9-427E-9852-FDB14ED5DB40"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.06.86:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C35A8A7C-49CD-4039-84E0-BF69286E69C9"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.07.00:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "3DCF41D0-4259-418A-B7BC-BC0A779A990A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.07.01:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9A684E73-28F5-45CB-98C8-D16C14EE2FB5"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.07.08:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A63BA260-2527-4E92-BB70-B351C3849855"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.07.09:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A0D4377B-FED5-4D0D-AA99-838F4BD79777"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.07.11:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0260871D-2CF7-4C7D-B7D1-B985B089190D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_pro:2.07.14:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9F981871-2AF4-4160-8056-29D8E0F5B900"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:*:*:*:*:*:*:*:*",
|
|
"versionEndIncluding": "2.07.16",
|
|
"matchCriteriaId": "DDE55F0A-2038-452C-BF36-D91E0281DCE8"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.00:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "47F58C24-BABB-4FC6-95E2-72F7F3211E67"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.03:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "358EA7A5-EC72-4767-B857-FB077EF318DB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.04:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "210F68AE-1801-4F1C-8456-3388BCA76913"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.06:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "6B5FFAAC-A327-4BDE-8313-D47CBB5161FF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.09:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2D7D7FD6-3B86-42E7-B039-9C3570DB6813"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.10:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "831D86C8-2C16-435D-A3E7-7E2B3FCABDA2"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.12:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "115F4E5E-4C00-4B3E-B34F-6FE0F322E591"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.13:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "698B9BC0-5F57-4624-AEC6-864B4E4B1CE7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.14:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "564CD457-97F2-436F-9AFD-F9F82A6BD368"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.18:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F7398A76-C1C1-43BF-AFD3-A0B8177B63DF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.21:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5CF9E5D8-14E0-4506-A08D-97125F643279"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.24:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CE30B897-69DB-461C-A382-B7124A809ABE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.25:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "703A4316-7745-46AC-BC36-A110DEA57F16"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.28:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A9BCF347-6E14-4BC8-AA22-6825C68EE67E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.40:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C8C7FD60-29C2-40C5-BBD1-5C7426FE17FB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.46:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2DD79175-3D49-4951-9F8F-47DDCDCD681D"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.50:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "30FF1930-4632-4ED2-A135-DE9418AFDDBA"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.60:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CEB19780-F6C7-44C5-8FBE-19A40EF94648"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.73:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "54739E92-66BF-4A19-881B-DBA335B29967"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.06.86:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "CDCEFDF8-178A-42FE-A8D6-7C104E6F2F5B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.07.00:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "110EDA4F-6790-40CF-846D-11622858A2E4"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.07.01:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "BA670181-0918-41F5-8AAE-684720ACFBF7"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.07.08:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A05C562A-2760-4541-BD33-CF6B0F3C5E41"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.07.09:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2A2B5F48-2ECA-423D-83C1-FA49D8EED361"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.07.11:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "F83CFE33-7559-463C-A518-1F9FCBEB82F8"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:sielcosistemi:winlog_lite:2.07.14:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "41350C83-559C-4564-84FB-401917686921"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://aluigi.org/adv/winlog_2-adv.txt",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Exploit"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://secunia.com/advisories/49395",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.sielcosistemi.com/en/news/index.html?id=69",
|
|
"source": "cve@mitre.org"
|
|
},
|
|
{
|
|
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"US Government Resource"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://aluigi.org/adv/winlog_2-adv.txt",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Exploit"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://secunia.com/advisories/49395",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
},
|
|
{
|
|
"url": "http://www.sielcosistemi.com/en/news/index.html?id=69",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-213-01.pdf",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108",
|
|
"tags": [
|
|
"US Government Resource"
|
|
]
|
|
}
|
|
]
|
|
} |