CINXE.COM
CVSS v4.0 Examples
<!doctype html><html lang="en" class="web tlp-clear" data-studio-config="eyJ4aHJDcmVkZW50aWFscyI6ZmFsc2UsInhockhlYWRlcnMiOnt9fQo="><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><title>CVSS v4.0 Examples</title> <meta property="og:title" content="CVSS v4.0 Examples" /> <meta property="og:type" content="website" /> <meta property="og:image" content="https://www.first.org/cvss/identity/cvssv4.png" /> <meta property="og:url" content="https://www.first.org/cvss/v4.0/examples" /> <meta property="og:site_name" content="FIRST — Forum of Incident Response and Security Teams" /> <meta property="fb:profile_id" content="296983660669109" /> <meta property="twitter:card" content="summary_large_image" /> <meta property="twitter:site" content="@FIRSTdotOrg" /> <meta property="twitter:image" content="https://www.first.org/cvss/identity/cvssv4.png" /><meta name="viewport" content="initial-scale=1,maximum-scale=1.0,user-scalable=no" /><link rel="icon" type="image/png" href="/1st.png" /><link rel="apple-touch-icon" sizes="128x128" href="/favicon.png" /><link rel="stylesheet" type="text/css" href="/_/web.css?20241031194005" /></head><body><header><div id="header" data-studio="CU52CV1W8g"><div id="c3" data-studio="Yu8FjCC11g"><div id="topbar"> <div class="sites right"> <ul> <li><a href="https://support.first.org" class="kb-datalist"><img src="/_/img/icon-portal_support.svg" alt="FIRST Support" title="FIRST Support" /></a></li> <li><a href="https://portal.first.org" class="button"><span class="no-tiny">Member </span>Portal</a></li> </ul> </div> <div class="first-logo"> <p><a href="/"><img src="/_/img/first-org-simple-negative.svg" alt="FIRST.Org" title="FIRST" /></a></p> </div> <div class="nav"> <ul class="navbar"><li><a href="/about">About FIRST</a><ul><li><a href="/about/mission">Mission Statement</a></li><li><a href="/about/history">History</a></li><li><a href="/about/sdg">Sustainable Development Goals</a></li><li><a href="/about/organization">Organization</a><ul><li><a href="/about/organization/directors">Board of Directors</a></li><li><a>Operations Team</a><ul><li><a href="/about/organization/ccb">Community & Capacity Building</a></li><li><a href="/about/organization/events">Event Office</a></li><li><a href="/about/organization/executive-director">Executive Director</a></li><li><a href="/about/organization/infrastructure">Infrastructure</a></li><li><a href="/about/organization/secretariat">Secretariat</a></li></ul></li><li><a href="/about/organization/committees">Committees</a><ul><li><a href="/about/organization/committees/compensation-committee">Compensation Committee</a></li><li><a href="/about/organization/committees/conference-program-committee">Conference Program Committee</a></li><li><a href="/about/organization/committees/membership-committee">Membership Committee</a></li><li><a href="/about/organization/committees/rules-committee">Rules Committee</a></li><li><a href="/about/organization/committees/standards">Standards Committee</a></li></ul></li><li><a href="/events/agm">Annual General Meeting</a></li><li><a href="/about/organization/reports">Annual Reports and Tax Filings</a></li></ul></li><li><a href="/about/policies">FIRST Policies</a><ul><li><a href="/about/policies/anti-corruption">Anti-Corruption Policy</a></li><li><a href="/about/policies/antitrust">Antitrust Policy</a></li><li><a href="/about/policies/bylaws">Bylaws</a></li><li><a href="/about/policies/board-duties">Board duties</a></li><li><a href="/about/bugs">Bug Bounty Program</a></li><li><a href="/about/policies/code-of-conduct">Code of Conduct</a></li><li><a href="/about/policies/conflict-policy">Conflict of Interest Policy</a></li><li><a href="/about/policies/doc-rec-retention-policy">Document Record Retention and Destruction Policy</a></li><li><a href="/newsroom/policy">FIRST Press Policy</a></li><li><a href="/about/policies/gen-event-reg-refund-policy">General Event Registration Refund Policy</a></li><li><a href="/about/policies/event-site-selection">Guidelines for Site Selection for all FIRST events</a></li><li><a href="/identity">Identity & Logo Usage</a></li><li><a href="/about/policies/mailing-list">Mailing List Policy</a></li><li><a href="/about/policies/media">Media Policy</a></li><li><a href="/about/policies/privacy">Privacy Policy</a></li><li><a href="/about/policies/registration-terms-conditions">Registration Terms & Conditions</a></li><li><a href="/about/policies/terms">Services Terms of Use</a></li><li><a href="/about/policies/standards">Standards Policy</a></li><li><a href="/about/policies/diversity">Statement on Diversity & Inclusion</a></li><li><a href="/about/policies/translation-policy">Translation Policy</a></li><li><a href="/about/policies/travel-policy">Travel Policy</a></li><li><a href="/about/policies/uniform-ipr">Uniform IPR Policy</a></li><li><a href="/about/policies/whistleblower-policy">Whistleblower Protection Policy</a></li></ul></li><li><a href="/about/partners">Partnerships</a><ul><li><a href="/global/partners">Partners</a></li><li><a href="/global/friends">Friends of FIRST</a></li><li><a href="/global/supporters/">FIRST Supporters</a></li><li><a href="/about/sponsors">Sponsors</a></li></ul></li><li><a href="/newsroom">Newsroom</a><ul><li><a href="/newsroom/news">What's New</a></li><li><a href="/newsroom/releases">Press Releases</a></li><li><a href="/newsroom/news/media">In the News</a></li><li><a href="/podcasts">Podcasts</a><ul><li><a href="/newsroom/news/first-impressions/">FIRST Impressions Podcast</a></li><li><a href="/newsroom/news/podcasts/">FIRSTCON Podcast</a></li></ul></li><li><a href="/newsroom/newsletters">Newsletters</a></li><li><a href="/newsroom/policy">FIRST Press Policy</a></li></ul></li><li><a href="/about/procurement">Procurement</a></li><li><a href="/about/jobs/">Jobs</a></li><li><a href="/contact">Contact</a></li></ul></li><li><a href="/members">Membership</a><ul><li><a href="/membership/">Becoming a Member</a><ul><li><a href="/membership/process">Membership Process for Teams</a></li><li><a href="/membership/process-liaisons">Membership Process for Liaisons</a></li><li><a href="/membership/#Fees">Membership Fees</a></li></ul></li><li><a href="/members/teams">FIRST Teams</a></li><li><a href="/members/liaisons">FIRST Liaisons</a></li><li><a href="/members/map">Members around the world</a></li></ul></li><li><a href="/global">Initiatives</a><ul><li><a href="/global/sigs">Special Interest Groups (SIGs)</a><ul><li><a href="/global/sigs/framework">SIGs Framework</a></li><li><a href="/global/sigs/academicsec" class="borderb">Academic Security SIG</a></li><li><a href="/global/sigs/ai-security">AI Security SIG</a></li><li><a href="/global/sigs/automation">Automation SIG</a></li><li><a href="/global/sigs/bigdata">Big Data SIG</a></li><li><a href="/cvss">Common Vulnerability Scoring System (CVSS-SIG)</a><ul><li><a href="/cvss/calculator/4.0">Calculator</a></li><li><a href="/cvss/v4.0/specification-document">Specification Document</a></li><li><a href="/cvss/v4.0/user-guide">User Guide</a></li><li><a href="/cvss/v4.0/examples">Examples</a></li><li><a href="/cvss/v4.0/faq">Frequently Asked Questions</a></li><li><a href="/cvss/v4-0">CVSS v4.0 Documentation & Resources</a><ul><li><a href="/cvss/calculator/4.0">CVSS v4.0 Calculator</a></li><li><a href="/cvss/v4.0/specification-document">CVSS v4.0 Specification Document</a></li><li><a href="/cvss/v4.0/user-guide">CVSS v4.0 User Guide</a></li><li><a href="/cvss/v4.0/examples">CVSS v4.0 Examples</a></li><li><a href="/cvss/v4.0/faq">CVSS v4.0 FAQ</a></li></ul></li><li><a href="/cvss/v3-1">CVSS v3.1 Archive</a><ul><li><a href="/cvss/calculator/3.1">CVSS v3.1 Calculator</a></li><li><a href="/cvss/v3.1/specification-document">CVSS v3.1 Specification Document</a></li><li><a href="/cvss/v3.1/user-guide">CVSS v3.1 User Guide</a></li><li><a href="/cvss/v3.1/examples">CVSS v3.1 Examples</a></li><li><a href="/cvss/v3.1/use-design">CVSS v3.1 Calculator Use & Design</a></li></ul></li><li><a href="/cvss/v3-0">CVSS v3.0 Archive</a><ul><li><a href="/cvss/calculator/3.0">CVSS v3.0 Calculator</a></li><li><a href="/cvss/v3.0/specification-document">CVSS v3.0 Specification Document</a></li><li><a href="/cvss/v3.0/user-guide">CVSS v3.0 User Guide</a></li><li><a href="/cvss/v3.0/examples">CVSS v3.0 Examples</a></li><li><a href="/cvss/v3.0/use-design">CVSS v3.0 Calculator Use & Design</a></li></ul></li><li><a href="/cvss/v2">CVSS v2 Archive</a><ul><li><a href="/cvss/v2/guide">CVSS v2 Complete Documentation</a></li><li><a href="/cvss/v2/history">CVSS v2 History</a></li><li><a href="/cvss/v2/team">CVSS-SIG team</a></li><li><a href="/cvss/v2/meetings">SIG Meetings</a></li><li><a href="/cvss/v2/faq">Frequently Asked Questions</a></li><li><a href="/cvss/v2/adopters">CVSS Adopters</a></li><li><a href="/cvss/v2/links">CVSS Links</a></li></ul></li><li><a href="/cvss/v1">CVSS v1 Archive</a><ul><li><a href="/cvss/v1/intro">Introduction to CVSS</a></li><li><a href="/cvss/v1/faq">Frequently Asked Questions</a></li><li><a href="/cvss/v1/guide">Complete CVSS v1 Guide</a></li></ul></li><li><a href="/cvss/data-representations">JSON & XML Data Representations</a></li><li><a href="/cvss/training">CVSS On-Line Training Course</a></li><li><a href="/cvss/identity">Identity & logo usage</a></li></ul></li><li><a href="/global/sigs/csirt">CSIRT Framework Development SIG</a></li><li><a href="/global/sigs/cyberinsurance">Cyber Insurance SIG</a><ul><li><a href="/global/sigs/cyberinsurance/events">Cyber Insurance SIG Webinars</a></li></ul></li><li><a href="/global/sigs/cti">Cyber Threat Intelligence SIG</a><ul><li><a href="/global/sigs/cti/curriculum/">Curriculum</a><ul><li><a href="/global/sigs/cti/curriculum/introduction">Introduction</a></li><li><a href="/global/sigs/cti/curriculum/cti-introduction">Introduction to CTI as a General topic</a></li><li><a href="/global/sigs/cti/curriculum/methods-methodology">Methods and Methodology</a></li><li><a href="/global/sigs/cti/curriculum/pir">Priority Intelligence Requirement (PIR)</a></li><li><a href="/global/sigs/cti/curriculum/source-evaluation">Source Evaluation and Information Reliability</a></li><li><a href="/global/sigs/cti/curriculum/machine-human">Machine and Human Analysis Techniques (and Intelligence Cycle)</a></li><li><a href="/global/sigs/cti/curriculum/threat-modelling">Threat Modelling</a></li><li><a href="/global/sigs/cti/curriculum/training">Training</a></li><li><a href="/global/sigs/cti/curriculum/standards">Standards</a></li><li><a href="/global/sigs/cti/curriculum/glossary">Glossary</a></li><li><a href="/global/sigs/cti/curriculum/cti-reporting/">Communicating Uncertainties in CTI Reporting</a></li></ul></li><li><a href="/global/sigs/cti/events/">Webinars and Online Training</a></li><li><a href="/global/sigs/cti/cti-program">Building a CTI program and team</a><ul><li><a href="/global/sigs/cti/cti-program/program-stages">Program maturity stages</a><ul><li><a href="/global/sigs/cti/cti-program/stage1">CTI Maturity model - Stage 1</a></li><li><a href="/global/sigs/cti/cti-program/stage2">CTI Maturity model - Stage 2</a></li><li><a href="/global/sigs/cti/cti-program/stage3">CTI Maturity model - Stage 3</a></li></ul></li><li><a href="/global/sigs/cti/cti-program/starter-kit">Program Starter Kit</a></li><li><a href="/global/sigs/cti/cti-program/resources">Resources and supporting materials</a></li></ul></li></ul></li><li><a href="/global/sigs/digital-safety">Digital Safety SIG</a></li><li><a href="/global/sigs/dns">DNS Abuse SIG</a><ul><li><a href="/global/sigs/dns/policies">Code of Conduct & Other Policies</a></li><li><a href="/global/sigs/dns/dns-abuse-examples">Examples of DNS Abuse</a></li></ul></li><li><a href="/global/sigs/ethics">Ethics SIG</a><ul><li><a href="/global/sigs/ethics/ethics-first">Ethics for Incident Response Teams</a></li></ul></li><li><a href="/epss/">Exploit Prediction Scoring System (EPSS)</a><ul><li><a href="/epss/model">The EPSS Model</a></li><li><a href="/epss/data_stats">Data and Statistics</a></li><li><a href="/epss/user-guide">User Guide</a></li><li><a href="/epss/research">EPSS Research and Presentations</a></li><li><a href="/epss/faq">Frequently Asked Questions</a></li><li><a href="/epss/who_is_using">Who is using EPSS?</a></li><li><a href="/epss/epss_tools">Open-source EPSS Tools</a></li><li><a href="/epss/api">API</a></li><li><a href="/epss/papers">Related Exploit Research</a></li><li><a>Blog</a><ul><li><a href="/epss/articles/prob_percentile_bins">Understanding EPSS Probabilities and Percentiles</a></li><li><a href="/epss/articles/log4shell">Log4Shell Use Case</a></li><li><a href="/epss/articles/estimating_old_cvss">Estimating CVSS v3 Scores for 100,000 Older Vulnerabilities</a></li></ul></li><li><a href="/epss/partners">Data Partners</a></li></ul></li><li><a href="/global/sigs/msr/">FIRST Multi-Stakeholder Ransomware SIG</a></li><li><a href="/global/sigs/hfs/">Human Factors in Security SIG</a></li><li><a href="/global/sigs/ics">Industrial Control Systems SIG (ICS-SIG)</a></li><li><a href="/global/sigs/iep">Information Exchange Policy SIG (IEP-SIG)</a></li><li><a href="/global/sigs/information-sharing">Information Sharing SIG</a><ul><li><a href="/global/sigs/information-sharing/misp">Malware Information Sharing Platform</a></li></ul></li><li><a href="/global/sigs/le">Law Enforcement SIG</a></li><li><a href="/global/sigs/malware">Malware Analysis SIG</a><ul><li><a href="/global/sigs/malware/ma-framework">Malware Analysis Framework</a></li><li><a href="/global/sigs/malware/ma-framework/malwaretools">Malware Analysis Tools</a></li></ul></li><li><a href="/global/sigs/metrics">Metrics SIG</a><ul><li><a href="/global/sigs/metrics/events">Metrics SIG Webinars</a></li></ul></li><li><a href="/global/sigs/netsec/">NETSEC SIG</a></li><li><a href="/global/sigs/passive-dns">Passive DNS Exchange</a></li><li><a href="/global/sigs/policy">Policy SIG</a></li><li><a href="/global/sigs/psirt">PSIRT SIG</a></li><li><a href="/global/sigs/red-team">Red Team SIG</a></li><li><a href="/global/sigs/cpg">Retail and Consumer Packaged Goods (CPG) SIG</a></li><li><a href="/global/sigs/ctf">Security Lounge SIG</a></li><li><a href="/global/sigs/tic/">Threat Intel Coalition SIG</a><ul><li><a href="/global/sigs/tic/membership-rules">Membership Requirements and Veto Rules</a></li></ul></li><li><a href="/global/sigs/tlp">Traffic Light Protocol (TLP-SIG)</a></li><li><a href="/global/sigs/transport">Transportation and Mobility SIG</a></li><li><a href="/global/sigs/vulnerability-coordination">Vulnerability Coordination</a><ul><li><a href="/global/sigs/vulnerability-coordination/multiparty">Multi-Party Vulnerability Coordination and Disclosure</a></li><li><a href="/global/sigs/vulnerability-coordination/multiparty/guidelines">Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure</a></li></ul></li><li><a href="/global/sigs/vrdx">Vulnerability Reporting and Data eXchange SIG (VRDX-SIG)</a><ul><li><a href="/global/sigs/vrdx/vdb-catalog">Vulnerability Database Catalog</a></li></ul></li><li><a href="/global/sigs/wof">Women of FIRST</a></li></ul></li><li><a href="/global/governance">Internet Governance</a></li><li><a href="/global/irt-database">IR Database</a></li><li><a href="/global/fellowship">Fellowship Program</a><ul><li><a href="https://portal.first.org/fellowship">Application Form</a></li></ul></li><li><a href="/global/mentorship">Mentorship Program</a></li><li><a href="/hof">IR Hall of Fame</a><ul><li><a href="/hof/inductees">Hall of Fame Inductees</a></li></ul></li><li><a href="/global/victim-notification">Victim Notification</a></li><li><a href="/volunteers/">Volunteers at FIRST</a><ul><li><a href="/volunteers/list">FIRST Volunteers</a></li><li><a href="/volunteers/participation">Volunteer Contribution Record</a></li></ul></li><li><a href="#new">Previous Activities</a><ul><li><a href="/global/practices">Best Practices Contest</a></li></ul></li></ul></li><li><a href="/standards">Standards & Publications</a><ul><li><a href="/standards">Standards</a><ul><li><a href="/cvss">Common Vulnerability Scoring System (CVSS-SIG)</a></li><li><a href="/tlp">Traffic Light Protocol (TLP)</a><ul><li><a href="/tlp/use-cases">TLP Use Cases</a></li></ul></li><li><a href="/standards/frameworks/">Service Frameworks</a><ul><li><a href="/standards/frameworks/csirts">CSIRT Services Framework</a></li><li><a href="/standards/frameworks/psirts">PSIRT Services Framework</a></li></ul></li><li><a href="/iep">Information Exchange Policy (IEP)</a><ul><li><a href="/iep/iep_framework_2_0">IEP 2.0 Framework</a></li><li><a href="/iep/iep-json-2_0">IEP 2.0 JSON Specification</a></li><li><a href="/iep/iep-polices">Standard IEP Policies</a><ul><li><a href="https://www.first.org/iep/2.0/first-tlp-iep.iepj">IEP TLP Policy File</a></li><li><a href="https://www.first.org/iep/2.0/first-unknown-iep.iepj">IEP Unknown Policy File</a></li></ul></li><li><a href="/iep/iep_v1_0">IEP 1.0 Archive</a></li></ul></li><li><a href="/global/sigs/passive-dns">Passive DNS Exchange</a></li><li><a href="/epss">Exploit Prediction Scoring System (EPSS)</a></li></ul></li><li><a href="/resources/papers">Publications</a></li></ul></li><li><a href="/events">Events</a></li><li><a href="/education">Education</a><ul><li><a href="/education/first-training">FIRST Training</a><ul><li><a href="/education/trainings">Training Courses</a></li><li><a href="/education/trainers">FIRST Trainers</a></li></ul></li></ul></li><li><a href="/blog">Blog</a></li></ul> </div> </div> <div id="home-buttons"> <p><a href="/join" data-title="Join"><img alt="Join" src="/_/img/icon-join.svg"><span class="tt-join">Join<span>Details about FIRST membership and joining as a full member or liaison.</span></span></a> <a href="/learn" data-title="Learn"><img alt="Learn" src="/_/img/icon-learn.svg"><span class="tt-learn">Learn<span>Training and workshop opportunities, and details about the FIRST learning platform.</span></span></a> <a href="/participate" data-title="Participate"><img alt="Participate" src="/_/img/icon-participate.svg"><span class="tt-participate">Participate<span>Read about upcoming events, SIGs, and know what is going on.</span></span></a></p> </div></div></div></header><div id="body" data-studio="CU52CV1W8g"><div id="c1" data-studio="Yu8FjCC11g" class="data-preview toc-h1 toc-h2 toc-h3 code-border image-center"><p><img src="/cvss/identity/cvssv4_web.png" alt="CVSS logo" /></p> <h1 id="Common-Vulnerability-Scoring-System-v4-0-Examples">Common Vulnerability Scoring System v4.0: Examples</h1> <p>Also available <a href="/cvss/v4-0/cvss-v40-examples.pdf">in PDF format (707KiB)</a>.</p> <p>Document Version: 1.2</p> <p>The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. CVSS consists of four metric groups: Base, Threat, Environmental, and Supplemental. The Base group represents the intrinsic qualities of a vulnerability that are constant over time and across user environments, the Threat group reflects the characteristics of a vulnerability that change over time, and the Environmental group represents the characteristics of a vulnerability that are unique to a user's environment. Base metric values are combined with default values that assume the highest severity for Threat and Environmental metrics to produce a score ranging from 0 to 10. To further refine a resulting severity score, Threat and Environmental metrics can then be amended based on applicable threat intelligence and environmental considerations. Supplemental metrics do not modify the final score, and are used as additional insight into the characteristics of a vulnerability. A CVSS vector string consists of a compressed textual representation of the values used to derive the score. This document provides the official specification for CVSS version 4.0.</p> <p>CVSS is owned and managed by FIRST.Org, Inc. (FIRST), a US-based non-profit organization, whose mission is to help computer security incident response teams across the world. FIRST reserves the right to update CVSS and this document periodically at its sole discretion. While FIRST owns all right and interest in CVSS, it licenses it to the public freely for use, subject to the conditions below. Membership in FIRST is not required to use or implement CVSS. FIRST does, however, require that any individual or entity using CVSS give proper attribution, where applicable, that CVSS is owned by FIRST and used by permission. Further, FIRST requires as a condition of use that any individual or entity which publishes scores conforms to the guidelines described in this document and provides both the score and the scoring vector so others can understand how the score was derived.</p> <p><strong>Contents</strong></p> <h1 id="Resources-amp-Links">Resources & Links</h1> <p>Below are useful references to additional CVSS v4.0 documents.</p> <table> <thead> <tr> <th><strong>Resource</strong></th> <th><strong>Location</strong></th> </tr> </thead> <tbody> <tr> <td>Specification Document</td> <td>Includes metric descriptions, formulas, and vector strings. Available at <a href="https://www.first.org/cvss/v4.0/specification-document">https://www.first.org/cvss/v4.0/specification-document</a></td> </tr> <tr> <td>User Guide</td> <td>Includes further discussion of CVSS v4.0, a scoring rubric, and a glossary. Available at <a href="https://www.first.org/cvss/v4.0/user-guide">https://www.first.org/cvss/v4.0/user-guide</a></td> </tr> <tr> <td>Examples Document</td> <td>Includes examples of CVSS v4.0 scoring in practice. Available at <a href="https://www.first.org/cvss/examples">https://www.first.org/cvss/v4.0/examples</a></td> </tr> <tr> <td>CVSS v4.0 Calculator</td> <td>Reference implementation of the CVSS v4.0 equations, available at <a href="https://www.first.org/cvss/calculator/4.0">https://www.first.org/cvss/calculator/4.0</a></td> </tr> <tr> <td>JSON & XML Data Representations</td> <td>Schema definition available at <a href="https://www.first.org/cvss/data-representations">https://www.first.org/cvss/data-representations</a></td> </tr> <tr> <td>CVSS v4.0 Main Page</td> <td>Main page for all other CVSS resources: <a href="https://www.first.org/cvss/v4-0/">https://www.first.org/cvss/v4-0/</a></td> </tr> </tbody> </table> <h1 id="Introduction">Introduction</h1> <p>This document demonstrates how to apply the CVSS version 4.0 standard to assess specific vulnerabilities. Every vulnerability example includes a summary and a breakdown of the assessment. CVSS version 3.0 scores are provided to show differences between the two standards.</p> <p>Details of the vulnerabilities and attacks were sourced primarily from the National Vulnerability Database (NVD) at <a href="https://nvd.nist.gov/vuln/search">https://nvd.nist.gov/vuln/search</a>. Information from additional sources was also used when more details were required.</p> <p>Common Vulnerability Scoring System version 4.0 Examples</p> <p>The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. CVSS consists of four metric groups: Base, Threat, Environmental, and Supplemental. The Base group represents the intrinsic qualities of a vulnerability that are constant over time and across user environments, the Threat group reflects the characteristics of a vulnerability that change over time, and the Environmental group represents the characteristics of a vulnerability that are unique to a user's environment. Base metric values are combined with default values that assume the highest severity for Threat and Environmental metrics to produce a score ranging from 0 to 10. To further refine a resulting severity score, Threat and Environmental metrics can then be amended based on applicable threat intelligence and environmental considerations. Supplemental metrics do not modify the final score, and are used as additional insight into the characteristics of a vulnerability. A CVSS vector string consists of a compressed textual representation of the values used to derive the score. This document provides the official specification for CVSS version 4.0.</p> <p>The most current CVSS resources can be found at <a href="https://www.first.org/cvss/">https://www.first.org/cvss/</a></p> <p>CVSS is owned and managed by FIRST.Org, Inc. (FIRST), a US-based non-profit organization, whose mission is to help computer security incident response teams across the world. FIRST reserves the right to update CVSS and this document periodically at its sole discretion. While FIRST owns all rights and interest in CVSS, it licenses it to the public freely for use, subject to the conditions below. Membership in FIRST is not required to use or implement CVSS. FIRST does, however, require that any individual or entity using CVSS give proper attribution, where applicable, that CVSS is owned by FIRST and used by permission. Further, FIRST requires as a condition of use that any individual or entity which publishes scores conforms to the guidelines described in this document and provides both the score and the scoring vector so others can understand how the score was derived.</p> <h1 id="New-metric-coverage">New metric coverage</h1> <p>This section includes scoring examples that illustrate aspects of changed or modified metrics.</p> <h2 id="New-Metric-Attack-Requirements">New Metric – Attack Requirements</h2> <h3 id="CVE-2022-41741">CVE-2022-41741</h3> <p>A vulnerability in the module ngx_http_mp4_module might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The attack is only possible if an attacker can gain privileged access to the host running NGINX, place a specially crafted audio or video file within the webroot, and then trigger NGINX to process the specially crafted file.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>7.0</td> <td>7.3</td> </tr> <tr> <td>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 7.3</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>An attacker must be able to access the vulnerable system with a local, interactive session.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>Multiple conditions that require target specific reconnaissance and preparation must be satisfied in order to achieve successful exploitation of this vulnerability.</td> </tr> <tr> <td>Privileges Required</td> <td>Low</td> <td>An attacker must be able to place a file within the web root to be processed by NGINX.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>The attacker could execute arbitrary code on the vulnerable system with elevated privileges.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>The attacker could execute arbitrary code on the vulnerable system with elevated privileges.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The attacker could execute arbitrary code on the vulnerable system with elevated privileges.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to the subsequent system confidentiality.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to the subsequent system integrity.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to the subsequent system availability.</td> </tr> </tbody> </table> <h3 id="CVE-2020-3549">CVE-2020-3549</h3> <p>A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash.</p> <p>The vulnerability is due to insufficient sftunnel negotiation protection during initial device registration. An attacker in a man-in-the-middle position could exploit this vulnerability by intercepting a specific flow of the sftunnel communication between an FMC device and an FTD device. A successful exploit could allow the attacker to decrypt and modify the sftunnel communication between FMC and FTD devices, allowing the attacker to modify configuration data sent from an FMC device to an FTD device or alert data sent from an FTD device to an FMC device.</p> <table> <thead> <tr> <th></th> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Base</strong></td> <td>8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td>7.7 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td> </tr> <tr> <td><strong>Base + Threat</strong></td> <td></td> <td>5.2 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 5.2</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>An attacker must be on-path to be able to intercept communications between affected systems.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>Passive</td> <td>A user must be logged in and using the application for traffic to be generated that an attacker could capture.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could gain access to the system with a highly privileged user account.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker could gain access to the system with a highly privileged user account.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An attacker could gain access to the system with a highly privileged user account.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Unreported</td> <td>There is no known proof-of-concept code or malicious exploitation of this vulnerability.</td> </tr> </tbody> </table> <h3 id="CVE-2023-3089">CVE-2023-3089</h3> <p>Description: A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.</p> <table> <thead> <tr> <th></th> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Base</strong></td> <td>7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</td> <td>8.3 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N</a></td> </tr> <tr> <td><strong>Base + Environmental</strong></td> <td></td> <td>8.1 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/CR:H/IR:L/AR:L/MAV:N/MAC:H/MVC:H/MVI:L/MVA:L">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/CR:H/IR:L/AR:L/MAV:N/MAC:H/MVC:H/MVI:L/MVA:L</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Environmental 8.1</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>There is no inherent vulnerability, but a lower level of cryptography than expected was being used, resulting in a lower-than-configured certificate security.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>Attack requirements are present. Only applications built with a specific configuration are vulnerable.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>This CVE particularly affects high-security systems (FIPS users) and lowers the requirements to access confidential information.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>Low</td> <td>Integrity will be at a lower cryptographic level than desired, but is still always encrypted.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>Low</td> <td>Integrity will be at a lower cryptographic level than desired, but is still always encrypted.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Modified Attack Vector</td> <td>Network</td> <td>This still requires spoofing a cryptographically secure certificate, just not always an FIPS-approved algorithm.</td> </tr> <tr> <td>Modified Attack Complexity</td> <td>High</td> <td>This still requires spoofing a cryptographically secure certificate, just not always an FIPS-approved algorithm.</td> </tr> <tr> <td>Modified Vulnerable System Confidentiality</td> <td>High</td> <td>This still requires spoofing a cryptographically secure certificate, just not always an FIPS-approved algorithm.</td> </tr> <tr> <td>Modified Vulnerable System Integrity</td> <td>Low</td> <td>Integrity will be at a lower cryptographic level than desired, but is still always encrypted.</td> </tr> <tr> <td>Modified Vulnerable System Availability</td> <td>Low</td> <td>Integrity will be at a lower cryptographic level than desired, but is still always encrypted.</td> </tr> <tr> <td>Confidentiality Requirements</td> <td>High</td> <td>System certificates are still encrypted correctly, but at a weaker level than expected, resulting in a hard-to-abuse system, but easier than intended/designed for the system.</td> </tr> <tr> <td>Integrity Requirements</td> <td>Low</td> <td>There is a low chance of integrity being modified, but higher than expected behavior.</td> </tr> <tr> <td>Availability Requirements</td> <td>Low</td> <td>There is a low chance of availability being affected, but higher than expected behavior.</td> </tr> </tbody> </table> <h2 id="Revised-Metric-User-Interaction">Revised Metric – User Interaction</h2> <p>Analysts assessing User Interaction should consider the necessary actions taken by a user. As per the specification document, operations normally taken by a user would be User Interaction:Passive. Actions that are out of the ordinary, against recommended guidance, or subverting security controls, would be User Interaction:Active.</p> <h3 id="CVE-2021-44714">CVE-2021-44714</h3> <p>Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In affected versions, this warning message does not include custom protocols when used by the sender. User interaction is required to abuse this vulnerability as they would need to click 'allow' on the warning message of a malicious file.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>3.3</td> <td>4.6</td> </tr> <tr> <td>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 4.6</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>The document must be present on the local disk.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>Active</td> <td>User interaction is required to abuse this vulnerability because they would need to click <strong>allow</strong> on the warning message of a malicious file.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>Low</td> <td>Warning dialog messages do not contain all information about the document. Important omitted information about the document may allow the attacker to conduct further spoofing attacks.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact on vulnerable systems.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact on vulnerable systems.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h3 id="CVE-2022-21830">CVE-2022-21830</h3> <p>Description A blind self XSS vulnerability exists in RocketChat LiveChat \<v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.</p> <table> <thead> <tr> <th><strong>V3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>6.1</td> <td>5.1</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 5.1</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>Active</td> <td>The attacker must convince the user to input malicious script into the application.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>No impact to the vulnerable application.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>No impact to the vulnerable application.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>No impact to the vulnerable application.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>Low</td> <td>An attacker could read data from the user’s browser.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>An attacker could modify data in the user’s browser.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>No direct availability impact to the user’s browser.</td> </tr> </tbody> </table> <h2 id="New-Metric-Subsequent-Confidentiality-Availability-Integrity">New Metric – Subsequent Confidentiality, Availability, Integrity</h2> <p>Some examples of subsequent systems include:</p> <ul> <li> <p>Guest host in a VMM hypervisor</p> </li> <li> <p>Device attached to a network gateway</p> </li> <li> <p>A managed Device</p> <ul> <li>Including OT / ICS / SCADA equipment</li> </ul> </li> </ul> <h3 id="CVE-2022-22186">CVE-2022-22186</h3> <p>Due to an Improper Initialization vulnerability in Junos OS on EX4650 devices, packets received on the em0 but not destined to the device, may be improperly forwarded to an egress interface, instead of being discarded. Such traffic being sent by a client may appear genuine, but is non-standard in nature and should be considered as potentially malicious.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>7.2</td> <td>6.9</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 6.9</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>An attacker must be able to access the vulnerable system with a local, interactive session.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>Low</td> <td>Network traffic or information from restricted hosts may be detected.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>Network traffic may be sent to an undesired interface.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h3 id="CVE-2023-21989">CVE-2023-21989</h3> <p>Description</p> <p>Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attackers with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>6.0</td> <td>5.9</td> </tr> <tr> <td>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N">CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 5.9</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>An attacker must be able to access the vulnerable system with a local, interactive session.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>High</td> <td>An attacker must have administrative control over a virtual machine within the virtual machine host.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>An attacker could exploit this vulnerability to access confidential information stored within the VM host hypervisor system.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h3 id="CVE-2020-3947">CVE-2020-3947</h3> <p>VMware Workstation (15.x before 15.5.2) and Fusion (11.x before 11.5.2) contain a use-after vulnerability in vmnetdhcp. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to create a denial-of-service condition of the vmnetdhcp service running on the host machine.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>9.3</td> <td>9.4</td> </tr> <tr> <td>CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 9.4</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>An attacker must be able to access the vulnerable system with a local, interactive session.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>High</td> <td>An attacker must have administrative control over a virtual machine within the virtual machine host.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could execute arbitrary code on the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker could execute arbitrary code on the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An attacker could execute arbitrary code on the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>An attacker could take actions on other systems hosted within the virtual hypervisor.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>An attacker could take actions on other systems hosted within the virtual hypervisor.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>An attacker could take actions on other systems hosted within the virtual hypervisor.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Proof-of-Concept (P)</td> <td>A proof of concept is available</td> </tr> </tbody> </table> <h2 id="New-Metric-Safety">New Metric – Safety</h2> <p>Safety is a Supplemental metric which may be optionally assessed by a scoring provider with values of Not Defined (X), Present (P), or Negligible (N). In the case of a system that intends to have health-related functions, it might also have a Safety-related consequence if a vulnerability is exploited. Let’s look at an example.</p> <h3 id="CVE-2023-30560">CVE-2023-30560</h3> <p>There are two known configurations of a product known as the Becton Dickinson PCU which can be modified without authentication using physical connection to the PCU. A PCU is commonly used for infusion delivery in a healthcare provider environment. With that context in mind, it could be inferred that an exploit of this vulnerability might have Safety impact. The below is only an example of how this, or a similar vulnerability, <em>could</em> be scored.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>6.8</td> <td>8.3</td> </tr> <tr> <td>CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/S:P/V:D">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/S:P/V:D</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.3</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Physical</td> <td>An attacker must be able to physically access the system.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>An attacker is unauthorized prior to the attack.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could execute arbitrary code on the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker could execute arbitrary code on the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An attacker could execute arbitrary code on the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>If the scoring provider assumes that a patient is the subsequent system, a successful exploit would not result in loss of confidentiality.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>If the scoring provider assumes that a patient is the subsequent system, a successful exploit could result in loss of health integrity for that patient.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>If the scoring provider assumes that a patient is the subsequent system, the attribute of availability might be metaphorically ambiguous.</td> </tr> </tbody> </table> <p><strong>CVSS v4 Supplemental Metrics</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Safety</td> <td>Present</td> <td>Consequences of exploiting this vulnerability could have a Safety impact that is equal to or worse than “marginal”, as described in IEC 61508.</td> </tr> <tr> <td>Value Density</td> <td>Diffuse</td> <td>The system with the vulnerable component is fairly limited in resources.</td> </tr> </tbody> </table> <h1 id="Classic-Examples">Classic Examples</h1> <p>These were in the previous version and we are carrying them forward to show the change between version 3 and 4.</p> <h2 id="OpenSSL-Heartbleed-Vulnerability-CVE-2014-0160">OpenSSL Heartbleed Vulnerability (CVE-2014-0160)</h2> <p><strong>Vulnerability</strong></p> <p>The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.</p> <p><strong>Attack</strong></p> <p>A successful attack requires only sending a specially crafted message to a web server running OpenSSL. The attacker constructs a malformed “heartbeat request” with a large field length and small payload size. The vulnerable server does not validate the length of the payload against the provided field length and will return up to 64 kB of server memory to the attacker. It is likely that this memory was previously utilized by OpenSSL. Data returned may contain sensitive information such as encryption keys or user names and passwords that could be used by the attacker to launch further attacks</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base + Threat</strong></th> </tr> </thead> <tbody> <tr> <td>7.5</td> <td>8.7</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:A">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:A</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 8.7</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Access to only some restricted information is obtained, but the disclosed information presents a direct, serious impact to the affected scope (e.g. the attacker can read the administrator's password, or private keys in memory are disclosed to the attacker).</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Attacked</td> <td>There are known exploits in the wild.</td> </tr> </tbody> </table> <h2 id="Apache-log4j-JNDI-Command-Execution-log4shell-Vulnerability-CVE-2021-44228">Apache log4j JNDI Command Execution “log4shell” Vulnerability (CVE-2021-44228)</h2> <p>A vulnerability in the Apache log4j library could allow an unauthenticated, remote attacker to execute arbitrary commands with the privileges of the service using the vulnerable library.</p> <table> <thead> <tr> <th><strong>v3.1 Base</strong></th> <th><strong>v4.0 Base + Threat</strong></th> </tr> </thead> <tbody> <tr> <td>10.0</td> <td>10.0</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A</a></td> </tr> </tbody> </table> <p><strong>CVSS v3.1 Base Score: 10.0</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerability is in a network service that uses log4j.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No conditions outside of the user’s control.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>An attacker requires no privileges to mount an attack.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>The attacker requires no user interaction to successfully exploit the vulnerability</td> </tr> <tr> <td>Scope</td> <td>Changed</td> <td>The vulnerable component could allow an attacker to affect downstream components and systems.</td> </tr> <tr> <td>Confidentiality</td> <td>High</td> <td>An attacker can execute arbitrary commands with elevated privileges.</td> </tr> <tr> <td>Integrity</td> <td>High</td> <td>An attacker can execute arbitrary commands with elevated privileges.</td> </tr> <tr> <td>Availability</td> <td>High</td> <td>An attacker can execute arbitrary commands with elevated privileges.</td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 10.0</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>Although the attacker must prepare the environment to achieve the worst possible outcome of an attack, (for example, code execution) through control of a reachable LDAP server, the system should be assumed vulnerable.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>The attack does not require any user interaction.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>The attacker can run arbitrary commands with elevated privileges and access sensitive system information.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>The attacker can run arbitrary commands with elevated privileges and modify the system configuration.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The attacker can run arbitrary commands with elevated privileges and gain access sufficient to reset or turn off the device.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>The attacker could exploit the vulnerability to view sensitive information from downstream systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>The attacker could exploit the vulnerability to modify data from downstream systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>The attacker could exploit the vulnerability to impact the availability of downstream systems.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Attacked</td> <td>There are known exploits in the wild.</td> </tr> </tbody> </table> <h2 id="GNU-Bourne-Again-Shell-Bash-Shellshock-Vulnerability-CVE-2014-6271">GNU Bourne-Again Shell (Bash) ‘Shellshock’ Vulnerability (CVE-2014-6271)</h2> <p>Vulnerability</p> <p>GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "Shellshock."</p> <p>Attack</p> <p>A successful attack can be launched by an attacker directly against the vulnerable GNU Bash shell, or in certain cases, by an unauthenticated, remote attacker through services either written in GNU Bash or services spawning GNU Bash shells. In the case of an attack against the Apache HTTP Server running dynamic content CGI modules, an attacker can submit a request while providing specially crafted commands as environment variables. These commands will be interpreted by the handler program, the GNU Bash shell, with the privilege of the running HTTPD process. As such, environment variables passed by the attacker could allow installation of software, account enumeration, denial of service, etc. Attacks against other services that have a relationship with the GNU Bash shell are similarly possible.</p> <table> <thead> <tr> <th><strong>v3.1 Base</strong></th> <th><strong>v4.0 Base + Threat</strong></th> </tr> </thead> <tbody> <tr> <td>9.8</td> <td>9.3</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A</a></td> </tr> </tbody> </table> <p><strong>CVSS v3.1 Base Score: 9.8</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The reasonable worst-case scenario is a network attack through a web server.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>An attacker needs only to gain access to a listening service that uses the GNU Bash shell as an interpreter or interact with a GNU Bash shell directly.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>The reasonable worst-case scenario is an attack through a web server, which does not require any privileges, for example, a simple CGI script.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Scope</td> <td>Unchanged</td> <td>The vulnerable component is the GNU Bash shell, which is used as an interpreter for various services or can be accessed directly. It runs within the security authority of the operating system. The impacted component is also the operating system, so there is no scope change.</td> </tr> <tr> <td>Confidentiality</td> <td>High</td> <td>An attacker can take complete control of the affected system.</td> </tr> <tr> <td>Integrity</td> <td>High</td> <td>An attacker can take complete control of the affected system.</td> </tr> <tr> <td>Availability</td> <td>High</td> <td>An attacker can take complete control of the affected system.</td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 9.3</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>The attacker can run arbitrary commands with elevated privileges and access sensitive system information.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>The attacker can run arbitrary commands with elevated privileges and modify the system configuration.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The attacker can run arbitrary commands with elevated privileges and gain access sufficient to reset or turn off the device.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Attacked</td> <td>There are known exploits in the wild.</td> </tr> </tbody> </table> <h2 id="Juniper-Proxy-ARP-Denial-of-Service-Vulnerability-CVE-2013-6014">Juniper Proxy ARP Denial of Service Vulnerability (CVE-2013-6014)</h2> <p><strong>Vulnerability</strong></p> <p>If Proxy ARP is enabled on an unnumbered interface, an attacker can poison the ARP cache and create a bogus forwarding table entry for an IP address, effectively creating a denial of service for that subscriber or interface. When Proxy ARP is enabled on an unnumbered interface, the router will answer any ARP message from any IP address which could lead to exploitable information disclosure. This issue can affect any product or platform running Junos OS 10.4, 11.4, 11.4X27, 12.1, 12.1X44, 12.1X45, 12.2, 12.3, or 13.1, supporting unnumbered interfaces.</p> <p><strong>Attack</strong></p> <p>Exploitation of this vulnerability requires network adjacency with the target system and the ability to generate arbitrary ARP replies sent to the connected interface. A rogue subscriber can poison the ARP cache and/or create a rogue forwarding table entry for an IP of choice, effectively obscuring that IP address or redirecting IP traffic to the attacker.</p> <p>The resultant impact can be observed as unauthorized modification of a database on the vulnerable component, or as an impact on confidentiality or availability on attached devices (impacted component). Since the CVSSv3 score for a high confidentiality (or availability) impact on a changed scope is higher than a partial impact on the vulnerable component, CVSSv3 guidance recommends to score for the higher overall impact.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>9.3</td> <td>6.4</td> </tr> <tr> <td>CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:H">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:H</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 6.4</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Adjacent</td> <td>The attacker must be within the local proximity of the device.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>Low</td> <td>Unauthorized modification of a database on the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>The attacker can hijack and redirect the IP traffic to themselves.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to the subsequent system integrity.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>Adding the rogue forwarding table can redirect the end user to rogue IP addresses.</td> </tr> </tbody> </table> <h2 id="Lenovo-ThnkPwn-Exploit-CVE-2016-5729">Lenovo ThnkPwn Exploit (CVE-2016-5729)</h2> <p>Vulnerability</p> <p>The SmmRuntime BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.</p> <p>Attack</p> <p>Attacker creates a buffer in memory containing exploit code to be executed in SMM context. Attacker then creates a structure with a pointer to the exploit code’s entry point and triggers an SMI passing a reference to that structure. The SMM driver then calls the exploit code via the supplied function pointer.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base + Threat</strong></th> </tr> </thead> <tbody> <tr> <td>8.2</td> <td>9.3</td> </tr> <tr> <td>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/R:I">CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/R:I</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 9.3</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>An attacker must be able to execute code on the system.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>This attack leverages a failure to verify input parameters in the <strong>SmmRuntime</strong> driver and can be reproduced consistently with simple code.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>High</td> <td>The attacker must be able to run kernel level (ring 0) code on the affected system.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>The vulnerability is built into the BIOS and is always available. There is no user configuration involved.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>SMM has complete control over the system, including all information on the system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>SMM access allows an attacker to modify any part of the system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The attacker could keep the system in SMM, denying access to the system and never returning to a normal operation mode.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>All software on the vulnerable system can be seen by the attacker.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>All software on the vulnerable system can be modified by the attacker.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>The attacker could keep the system in SMM, denying access to software on the system.</td> </tr> <tr> <td>Recovery</td> <td>Irrecoverable</td> <td>The attacker could keep the system in SMM, and could prevent recovery of the system by automatically running their code and locking down the system to prevent a user from accessing it.</td> </tr> </tbody> </table> <h2 id="Failure-to-Lock-Flash-on-Resume-from-sleep-CVE-2015-2890">Failure to Lock Flash on Resume from sleep (CVE-2015-2890)</h2> <p>Vulnerability</p> <p>Some UEFI BIOS implementations failed to set Flash write protections such as the BIOS_CNTL locking on resume from the S3 suspend to RAM sleep state.</p> <p>Attack</p> <p>Attacker causes or waits until the system resumes from suspend, and then writes over the current BIOS image in Flash with a new BIOS image modified by the attacker.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base + Threat</strong></th> </tr> </thead> <tbody> <tr> <td>6.0</td> <td>8.7</td> </tr> <tr> <td>CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/R:I">CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/R:I</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 8.7</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>An attacker must be able to execute code on the system.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>An attacker has unfettered access to the Flash part on which the BIOS is stored.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>The vulnerability is introduced by firmware failing to enable correct flash memory protections upon the resume from S3 system sleep state.</td> </tr> <tr> <td>Privileges Required</td> <td>High</td> <td>An attacker must be able to run kernel level (ring 0) code on the target system, in order to access the Flash part.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker that can modify the BIOS image can install components to completely monitor and control the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker that can modify the BIOS image can modify anything on the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An attacker could cause a denial of service by corrupting the BIOS image or could encrypt the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>Any software on the system could be monitored by an agent installed in the BIOS on the vulnerable system.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>Any files on the system could be modified by an agent installed in the BIOS.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>An attacker could encrypt files on the system, preventing access.</td> </tr> <tr> <td>Recovery</td> <td>Irrecoverable</td> <td>An attacker could cause a denial of service through encryption or corruption, neither of which could be fixed by a user.</td> </tr> </tbody> </table> <h2 id="Intel-DCI-Issue-CVE-2018-3652">Intel DCI Issue (CVE-2018-3652)</h2> <p>Vulnerability</p> <p>Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.</p> <p>Attack</p> <p>An attacker with physical access can attach a debug device to the DCI interface and directly interrogate and control the processor state starting from very early in the boot process.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>7.6</td> <td>8.6</td> </tr> <tr> <td>CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H">CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.6</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Physical</td> <td>An attacker must have physical access to the DCI port in order to attach the debugging device.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>The debugging device is off-the-shelf hardware that can be purchased from Intel.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>Only physical presence is required; no system privileges are required.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker can view all memory and CPU instructions.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker can modify all contents of memory and control the CPU directly.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An attacker can cause a denial of service by stopping the CPU from executing the desired functionality.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>An attacker can view the contents of memory for programs on the vulnerable system.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>An attacker can modify the contents of memory for running applications and files on the vulnerable system.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>An attacker can modify and corrupt applications on the vulnerable system.</td> </tr> </tbody> </table> <h1 id="Common-Vulnerabilities-Classes">Common Vulnerabilities Classes</h1> <p>This section contains examples of commonly-seen vulnerabilities from across the industry. The examples here are meant to be illustrative of common issues, but should not be considered authoritative. Unique vulnerabilities may have different impacts.</p> <h2 id="regreSSHion-CVE-2024-6387">regreSSHion – CVE-2024-6387</h2> <p>Description</p> <p>A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.</p> <p>Notes:</p> <p>The scenario below assumes a standalone Linux-based system without dependent managed systems that has ASLR protections enabled.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base+Threat</strong></th> </tr> </thead> <tbody> <tr> <td>8.1</td> <td>8.2</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.2</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>An attacker must be able to connect to the system from a remote network.</td> </tr> <tr> <td>Attack Complexity</td> <td>High</td> <td>Attackers must be able to defeat mitigations on platforms where ASLR and other memory defenses are present.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>An attacker must defeat a race condition, making the exploit unreliable.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to completely compromise the affected system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to completely compromise the affected system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to completely compromise the affected system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no direct impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no direct impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no direct impact to subsequent systems.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Proof-of-concept</td> <td>A proof-of-concept that demonstrates the vulnerability is available publicly.</td> </tr> </tbody> </table> <p><strong>Variation 1: Login Mitigation</strong></p> <p>In this variation, the application of the mitigation to reduce LoginGraceTime to 0 prevents exploitation of arbitrary code execution. However, the modified configuration leaves the SSH service vulnerable to resource exhaustion attacks. The resulting assessment reflects only the potential to cause a denial of service (DoS) condition.</p> <p>The below score uses modified base metrics to reflect the changes to exploitability and impact values.</p> <p>Modified Attack Complexity and Modified Attack Requirements replace the base Attack Complexity and Attack Requirements. With the mitigation in place, an attacker must no longer defeat a race condition or memory protections to exhaust available connections.</p> <p>Modified Vulnerable System Confidentiality and Modified System Integrity values replace the base Vulnerable System Confidentiality and Vulnerable System Integrity. There are no longer impacts to system confidentiality or integrity with the mitigation in place.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base+Threat+Environmental</strong></th> </tr> </thead> <tbody> <tr> <td>8.1</td> <td>5.5</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/MAC:L/MAT:N/MVC:N/MVI:N/MVA:L">CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/MAC:L/MAT:N/MVC:N/MVI:N/MVA:L</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: BTE 5.5</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>An attacker can connect to the system from a remote network.</td> </tr> <tr> <td>Attack Complexity</td> <td>High</td> <td>Attackers must be able to defeat mitigations on platforms where ASLR and other memory defenses are present.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>An attacker must defeat a race condition, making the exploit unreliable.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to completely compromise the affected system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to completely compromise the affected system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to completely compromise the affected system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no direct impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no direct impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no direct impact to subsequent systems.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Proof-of-concept</td> <td>A proof-of-concept that demonstrates the vulnerability is available publicly.</td> </tr> <tr> <td>Modified Vulnerable System Confidentiality</td> <td>None</td> <td>With the mitigation in place, the attacker cannot impact system confidentiality.</td> </tr> <tr> <td>Modified Vulnerable System Integrity</td> <td>None</td> <td>With the mitigation in place, the attacker cannot impact system integrity.</td> </tr> <tr> <td>Modified Vulnerable System Availability</td> <td>Low</td> <td>The attacker could exhaust available connections, rendering the SSH service unavailable.</td> </tr> </tbody> </table> <h2 id="SQL-Injection-CVE-2023-30545">SQL Injection – CVE-2023-30545</h2> <p>Description</p> <p>PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -> Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a `SELECT` request. This gives the user access to critical information. A patch is available in PrestaShop 8.0.4 and PS 1.7.8.9</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>6.5</td> <td>7.1</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 7.1</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>Low</td> <td>Attacker has to have database access (non-root user access).</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker can read any file on the operating system</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems Confidentiality.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems Integrity.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems Availability.</td> </tr> </tbody> </table> <h2 id="On-path-Attacker-CVE-2021-23846">On-path Attacker – CVE-2021-23846</h2> <p>Description</p> <p>Firmware for Bosch devices transmits in clear text over HTTP, allowing on-path attackers to gain access to user credentials.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>5.9</td> <td>8.2</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.2</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>An attacker must be on-path to be able to intercept communications between affected systems.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could access plain text user credentials.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h2 id="Denial-of-Service-CVE-2023-22394">Denial of Service – CVE-2023-22394</h2> <p>Description</p> <p>Memory leak due to receipt of specially crafted SIP calls (CVE-2023-22394)</p> <p>An Improper Handling of Unexpected Data Type vulnerability in the handling of SIP calls in Junos OS on SRX Series and MX Series platforms allows an attacker to cause a memory leak leading to Denial of Services (DoS).</p> <table> <thead> <tr> <th></th> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Base</strong></td> <td>7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</td> <td>8.7 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L</a></td> </tr> <tr> <td><strong>Base + Threat</strong></td> <td></td> <td>6.6 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:U">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:U</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 6.6</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An <strong>Improper Handling of Unexpected Data Type</strong> vulnerability in the handling of SIP calls in Juniper Networks Junos OS on SRX Series and MX Series platforms allows an attacker to cause a memory leak leading to denial of service.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no confidentiality impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to the integrity of subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>Low</td> <td>The subsequent device could be unavailable/unreachable for a brief period of time.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Unreported</td> <td>There is no known proof-of-concept or malicious exploitation of this vulnerability.</td> </tr> </tbody> </table> <h2 id="Cross-Site-Scripting-Reflected-CVE-2022-24682">Cross-Site Scripting (Reflected) – CVE-2022-24682</h2> <p>Categories: XSS</p> <p>An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021. An attacker could place HTML containing executable JavaScript inside element attributes. This markup becomes unescaped, causing arbitrary markup to be injected into the document.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>6.1</td> <td>5.1</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 5.1</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>Active</td> <td>A targeted user must click a malicious link that is provided by an attacker.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no direct impact to the web application confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no direct impact to the web application integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no direct impact to the web application availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>Low</td> <td>An attacker could read data from the user’s browser.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>An attacker could modify data in the user’s browser.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no direct availability impact to the user’s browser.</td> </tr> </tbody> </table> <h2 id="Cross-Site-Scripting-Stored-CVE-2020-0926">Cross-Site Scripting (Stored) – CVE-2020-0926</h2> <p>Microsoft Office SharePoint XSS Vulnerability</p> <p>Description</p> <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.</p> <p>An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. The attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on the SharePoint site on behalf of the user, such as change permissions and delete content, and inject malicious content in the browser of the user.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>5.4</td> <td>5.1</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 5.1</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>Low</td> <td>The attacker requires privileges sufficient to store data within the application.</td> </tr> <tr> <td>User Interaction</td> <td>Passive</td> <td>A targeted user must browse to the application as part of normal operations.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no direct impact to the web application confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no direct impact to the web application integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no direct impact to the web application availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>Low</td> <td>An attacker can read content that the attacker is not authorized to read from the user's browser.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>An attacker could inject malicious content that could be executed within the user’s browser.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no direct impact to the user’s browser availability.</td> </tr> </tbody> </table> <h2 id="Cross-Site-Request-Forgery-CVE-2023-5602">Cross-Site Request Forgery – CVE-2023-5602</h2> <p>WordPress Social Media Share Buttons & Social Sharing Icons Cross-Site Request Forgery</p> <p>Description</p> <p>The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated attackers to invoke those actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>4.3</td> <td>5.1</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 5.1</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>Active</td> <td>A targeted user must actively click on a malicious link that is provided by an attacker to initiate the attack sequence.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no direct impact to the web application confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>Low</td> <td>The attacker could modify some values within the web application.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no direct impact to the web application availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h2 id="Privilege-Escalation-Unprivileged-CVE-2022-20759">Privilege Escalation (Unprivileged) CVE-2022-20759</h2> <p>Description</p> <p>Cisco Adaptive Security Appliance Firepower Threat Defense (FTD) Privilege Escalation Vulnerability (CVE-2022-20759)</p> <p>A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privileges to level 15.</p> <p>An attacker could exploit this vulnerability by sending crafted HTTPS messages to the web services interface of an affected device. A successful exploit could allow the attacker to gain privilege level 15 access to the web management interface of the device.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>8.8</td> <td>7.7</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 7.7</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>Attacks are executed through HTTPS requests.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No advanced knowledge is required</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>HTTP Management Access <em>and</em> IKEv2 Client Service must be enabled on at least one interface, or HTTP management interface <em>and</em> WebVPN must be enabled on at least one interface.</td> </tr> <tr> <td>Privileges Required</td> <td>Low</td> <td>An attacker must have valid credentials for the VPN.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No additional user interaction is required for successful exploitation.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Successful exploitation could result in a complete compromise (enable 15) of the targeted device, which results in a complete (High) impact on the confidentiality of the device.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>Successful exploitation could result in a complete compromise resulting in High integrity impact.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>Successful exploitation could result in a complete compromise resulting in High availability impact.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h2 id="Privilege-Escalation-Highly-Privileged-CVE-2021-34724">Privilege Escalation (Highly Privileged) CVE-2021-34724</h2> <p>Description</p> <p>A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device as a PRIV15 administrative user.</p> <table> <thead> <tr> <th></th> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Base</strong></td> <td>6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</td> <td>8.3 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:L/AC:L/AT:N/</a><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N">PR:H</a><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N">/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N</a></td> </tr> <tr> <td><strong>Base + Threat</strong></td> <td></td> <td>5.6 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U">CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 5.6</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>An attacker must be able to access the vulnerable system with a local, interactive session.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>High</td> <td>An attacker must have administrator privileges within the affected system.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No additional user interaction is required for exploit</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could execute arbitrary commands on the affected system with the privileges of the <em>root</em> user, allowing the privileged attacker to access sensitive files that would otherwise be inaccessible to the administrative user.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker could execute arbitrary commands on the affected system with the privileges of the <em>root</em> user, allowing the privileged attacker to modify system values that would otherwise be inaccessible to the administrative user.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>An attacker does not gain any additional privileges to impact system availability. Privileges required to exploit this vulnerability already allow the attacker to turn off the system, so there is no privilege gain as a result of exploitation.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Unreported</td> <td>There is no known proof-of-concept code or malicious exploitation of this vulnerability.</td> </tr> </tbody> </table> <h2 id="Remote-Code-Execution-CVE-2023-28311">Remote Code Execution (CVE-2023-28311)</h2> <p>Microsoft Word Remote Code Execution Vulnerability</p> <p>An attacker must send the user a malicious file and convince the user to open said file which results in RCE.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>7.8</td> <td>8.5</td> </tr> <tr> <td>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.5</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>The document must be present on the local disk.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>Nothing outside of the attacker’s control.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>Passive</td> <td>A user must open a document.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to compromise the affected system completely.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to compromise the affected system completely.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The attacker could execute arbitrary code, which could allow the attacker to compromise the affected system completely.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h2 id="Arbitrary-Code-Execution-CVE-2022-22965">Arbitrary Code Execution CVE-2022-22965</h2> <p>Spring4shell</p> <p>A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.</p> <p>Attack</p> <p>An RCE can be established by simply sending a series of malicious web requests to a web server running on a vulnerable version of Spring. Spring4Shell allows attackers to get arbitrary code execution in the context of the user that is running the vulnerable application. Once the attackers achieve RCE, they can install malware or can use the server as an initial foothold to escalate privileges and compromise the whole system, or even access subsequent backend systems that the vulnerable server has privileged access to.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base + Threat</strong></th> </tr> </thead> <tbody> <tr> <td>9.8</td> <td>9.2</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A">CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Threat 9.2</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>A successful attack depends on the deployment and execution conditions of the vulnerable system.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>The vulnerability allows an attacker to execute arbitrary code in the context of the user that is running the vulnerable application and gain complete control over the system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>The vulnerability allows an attacker to execute arbitrary code in the context of the user that is running the vulnerable application and gain complete control over the system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>The vulnerability allows an attacker to execute arbitrary code in the context of the user that is running the vulnerable application and gain complete control over the system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no immediate loss of confidentiality within the subsequent systems. But, based on how Spring is deployed in the target environment, the compromised server could be used as a pivot to leverage further. If there are subsequent impacts, they should be defined in environmental metrics.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no immediate loss of integrity within the subsequent systems. But, based on how Spring is deployed in the target environment, the compromised server could be used as a pivot to leverage further. If there are subsequent impacts, they should be defined in environmental metrics.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no immediate loss of availability within the subsequent system. But, based on how Spring is deployed in the target environment, the compromised server could be used as a pivot to leverage further. If there are subsequent impacts, they should be defined in environmental metrics.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Attacked</td> <td>There are known exploits in the wild.</td> </tr> </tbody> </table> <h2 id="Physical-Access-CVE-2022-20826">Physical Access (CVE-2022-20826)</h2> <p>A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attacker with physical access to the device to bypass the secure boot functionality. This vulnerability is due to a logic error in the boot process. An attacker could exploit this vulnerability by injecting malicious code into a specific memory location during the boot process of an affected device. A successful exploit could allow the attacker to execute persistent code at boot time and break the chain of trust.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>6.4</td> <td>5.4</td> </tr> <tr> <td>CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 5.4</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Physical</td> <td>An attacker requires physical access to a vulnerable system.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>Present</td> <td>There are timing requirements outside the attacker’s control, making exploit attempts unreliable.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could inject malicious, unsigned code and execute arbitrary commands.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker could inject malicious, unsigned code and execute arbitrary commands.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An attacker could inject malicious, unsigned code and execute arbitrary commands.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h2 id="Information-Disclosure-CVE-2022-21500">Information Disclosure – CVE-2022-21500</h2> <p>Description</p> <p>Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data.</p> <p>Note: Authentication is required for successful attack, however the user may be self-registered. Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should refer to the Patch Availability Document for details.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>7.5</td> <td>8.7</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.7</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could exploit the vulnerability to access critical data that is stored within the vulnerable application.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h2 id="Information-Disclosure---CVE-2021-32570">Information Disclosure - CVE-2021-32570</h2> <p>In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in the ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>4.9</td> <td>6.9</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 6.9</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>High</td> <td>An attacker must have membership in the AMOS authorization group sufficient to read data from log files.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could exploit the vulnerability to view sensitive data within the application log files.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <h2 id="Command-Injection-CVE-2022-26134">Command Injection (CVE-2022-26134)</h2> <p>Description</p> <p>Atlassian Confluence Server and Data Center OGNL Injection Vulnerability (CVE-2022-26134)</p> <p>In Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance.</p> <p>A remote attacker could exploit it by requests injecting specially crafted OGNL templates in order to execute arbitrary code.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>9.8</td> <td>9.3</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 9.3</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>Attacks are executed through HTTP(s) requests and are accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No advanced knowledge is required</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Successful exploitation could result in a complete compromise (command execution as <em>root</em>) of the affected device, which results in a complete (High) impact on the confidentiality of the device.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>Successful exploitation could result in a complete compromise (command execution as <em>root</em>) of the affected device, which results in a complete (High) impact on the integrity of the device.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>Successful exploitation could result in a complete compromise (command execution as <em>root</em>) of the affected device, which results in a complete (High) impact on the availability of the device.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There are no additional impacts to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There are no additional impacts to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There are no additional impacts to subsequent systems.</td> </tr> </tbody> </table> <h2 id="ACL-Bypass-CVE-2023-20245">ACL Bypass (CVE-2023-20245)</h2> <p>A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic that should be denied to flow through an affected device. The vulnerability is due to a logic error that could occur when the affected software constructs and applies per-user-override rules. An attacker could exploit the vulnerability by connecting to a network through an affected device that has a vulnerable configuration. A successful exploit could allow the attacker to bypass the interface ACL and access resources that should be protected.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>5.8</td> <td>6.9</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 6.9</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>The attacker could send network traffic to downstream destinations that should otherwise be inaccessible.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> </tbody> </table> <p><strong>Variation 1: ACL Bypass with Downstream Impacts</strong></p> <p>In this example, we imagine a scenario in which the failure of an ACL to protect internal systems could result in impact to downstream systems.</p> <table> <thead> <tr> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td>7.8</td> </tr> <tr> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:H">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:H</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 7.8</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>Low</td> <td>The attacker could send network traffic through the device to downstream destinations that should otherwise be inaccessible.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>Low</td> <td>The attacker could gather information about or access services on subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>The attacker could send streams of network traffic that could overwhelm the subsequent system, resulting in a denial of service condition.</td> </tr> </tbody> </table> <h2 id="Server-Side-Request-Forgery-SSRF-CVE-2024-1233">Server-Side Request Forgery (SSRF) (CVE-2024-1233)</h2> <p>Description:</p> <p>A flaw was found in JwtValidator.resolvePublicKey in JBoss EAP, where the validator checks jku and sends a HTTP request. During this process, no whitelisting or other filtering behavior is performed on the destination URL address, which may result in a server-side request forgery (SSRF) vulnerability.</p> <p>Notes:</p> <p>Impacts for server-side request forgery vulnerabilities may depend on both the configuration of the vulnerable system as well as the presence of other systems in the environment that could be accessed as part of exploitation.</p> <p>The vulnerable system is the JBoss application server, while subsequent systems may be other applications on the same host or different back-end systems that are reachable by the vulnerable application server.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td>7.3</td> <td>6.9</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 6.9</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>An attacker must be able to send requests to an application that implements the vulnerable JBoss EAP feature.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No built-in security-enhancing conditions exist within the product to inhibit successful exploitation.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>The attacker can execute the exploit with no specific difficulty. No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>Low</td> <td>The attacker could cause the vulnerable system to send arbitrary HTTP requests.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>Low</td> <td>The attacker could cause the vulnerable system to send HTTP requests on the attacker’s behalf to another system, potentially allowing the attacker to gain information about or from a subsequent system.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>The attacker could send HTTP requests to another system and modify the application state of a subsequent system.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>Low</td> <td>The attacker could send HTTP requests to another system and potentially impact the availability of a subsequent system.</td> </tr> </tbody> </table> <p><strong>Variation 1:</strong></p> <p>In this variation, the system implementing the vulnerable JBoss EAP application allows access only to limited endpoints, reducing the subsequent system impact to Confidentiality only, allowing the attacker to gather information about systems that should be unreachable. This represents a more typical impact of a SSRF vulnerability.</p> <p>In the metric strings below, the Modified Subsequent System Integrity and Availability are selected as None and replace the base Subsequent System Integrity and Availability impacts.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td>7.3</td> <td>6.9</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/MSI:N/MSA:N">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L/MSI:N/MSA:N</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base+Environmental 6.9</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>An attacker must be able to send requests to an application that implements the vulnerable JBoss EAP feature.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No built-in security-enhancing conditions exist within the product to inhibit successful exploitation.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>The attacker can execute the exploit with no specific difficulty. No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>A user, other than the attacker, must be present for the vulnerability to be exploited. However, the actions taken by the user are typical, because a user must open a file within the vulnerable application.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>Low</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>Low</td> <td>The attacker could cause the vulnerable system to send HTTP requests on the attacker’s behalf to another system, potentially allowing the attacker to gain information about or from a subsequent system.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>The attacker could send HTTP requests to another system and modify the application state of a subsequent system. Note: the Modified Subsequent System Integrity replaces this metric.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>Low</td> <td>The attacker could send HTTP requests to another system and potentially impact the availability of a subsequent system. Note: the Modified Subsequent System Availability replaces this metric.</td> </tr> <tr> <td>Modified Subsequent System Integrity</td> <td>None</td> <td>No applications reachable by the vulnerable system accept HTTP requests, resulting in no integrity impact.</td> </tr> <tr> <td>Modified Subsequent System Availability</td> <td>None</td> <td>No applications reachable by the vulnerable system accept HTTP requests, resulting in no availability impact.</td> </tr> </tbody> </table> <h2 id="Industrial-Control-Systems-ICS-CVE-2023-28728">Industrial Control Systems (ICS) (CVE-2023-28728)</h2> <p>Description:</p> <p>In Panasonic Control FPWIN versions 7.6.0.3 and prior, a stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or a parameter to a function) when a file is opened within the application.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td>7.8</td> <td>8.5</td> </tr> <tr> <td>CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:P</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.5</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Local</td> <td>An attacker must be locally connected to the vulnerable system.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No built-in security-enhancing conditions exist within the product to inhibit successful exploitation.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>The attacker can execute the exploit with no specific difficulty. No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No privileges are required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>User Interaction</td> <td>Passive</td> <td>A user, other than the attacker, must be present for the vulnerability to be exploited. However, the actions taken by the user are typical, because a user must open a file within the vulnerable application.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>The impact on confidentiality is limited to the vulnerable system. No direct downstream impact is indicated.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>The impact on integrity is limited to the vulnerable system. No direct downstream impact is indicated.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>The impact on availability is limited to the vulnerable system. No direct downstream impact is indicated.</td> </tr> <tr> <td>Safety</td> <td>Present</td> <td>The impact from an attacker gaining full control of software that is running on a programmable logic controller (PLC) may meet the definition of IEC 61508 consequence category <strong>marginal</strong>, <strong>critical</strong> or <strong>catastrophic</strong> for certain usage of the PLC in an Operational Technology (OT) environment where humans may be harmed.</td> </tr> </tbody> </table> <h2 id="Operational-Technology-OT-CVE-2022-47379">Operational Technology (OT) (CVE-2022-47379)</h2> <p>An authenticated, remote attacker may use an out-of-bounds write vulnerability in multiple CODESYS products in multiple versions to write data into memory which can lead to a denial-of-service condition, memory overwriting, or remote code execution.</p> <table> <thead> <tr> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td>8.8</td> <td>9.4</td> </tr> <tr> <td>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</td> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/V:C/RE:L">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/V:C/RE:L</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 9.4</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Remote</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>The attacker can execute the exploit with no specific difficulty. No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>Low</td> <td>The attacker must require privileges sufficient to access the device.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>The attacker could impact the confidentiality of connected OT devices.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>The attacker could impact the confidentiality of connected OT devices.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>The attacker could impact the confidentiality of connected OT devices.</td> </tr> <tr> <td>Safety</td> <td>Present</td> <td>Connections to OT devices can impact the safety of humans and may meet the definition of IEC 61508 consequence category <strong>marginal</strong>, <strong>critical</strong> or <strong>catastrophic</strong> for certain usage in an Operational Technology (OT) environment where humans may be harmed.</td> </tr> <tr> <td>Automatable</td> <td>Yes</td> <td>Attacks against the vulnerability can be performed in an automated fashion with little oversight against multiple targets.</td> </tr> <tr> <td>Value Density</td> <td>Concentrated</td> <td>The value of OT devices in a facility has a highly concentrated value as a target.</td> </tr> <tr> <td>Vulnerability Response Effort</td> <td>Low</td> <td>A simple device reboot would correct the issue.</td> </tr> </tbody> </table> <p><strong>Variation 1: Elevator Operational Technology</strong></p> <p>In this variation of the vulnerability, the vulnerable device manages an elevator. The following metric score variation demonstrates the possible impacts of an exploit against such a deployment.</p> <table> <thead> <tr> <th><strong>B+E v4.0</strong></th> </tr> </thead> <tbody> <tr> <td>7.0</td> </tr> <tr> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:L/IR:H/AR:L/MAV:L/MAC:H/MAT:N/MPR:N/MUI:N/MVC:N/MVI:H/MVA:L/MSC:N/MSI:S/MSA:L">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:L/IR:H/AR:L/MAV:L/MAC:H/MAT:N/MPR:N/MUI:N/MVC:N/MVI:H/MVA:L/MSC:N/MSI:S/MSA:L</a></td> </tr> </tbody> </table> <p><strong>Variation 1: CVSS v4 Score: B+E 7.0</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>The attacker can execute the exploit with no specific difficulty. No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>Low</td> <td>The attacker must require privileges sufficient to access the device.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>The attacker could impact the confidentiality of connected OT devices.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>The attacker could impact the integrity of connected OT devices.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>The attacker could impact the availability of connected OT devices.</td> </tr> <tr> <td>Modified Attack Vector</td> <td>Local</td> <td>The system is disconnected from the Internet.</td> </tr> <tr> <td>Modified Attack Complexity</td> <td>High</td> <td>There are FW and Data Diodes that prevent access to the PLC.</td> </tr> <tr> <td>Modified Attack Requirements</td> <td>None</td> <td>Same as Base.</td> </tr> <tr> <td>Modified Privileges Required</td> <td>Low</td> <td>Same as Base.</td> </tr> <tr> <td>Modified User Interaction</td> <td>None</td> <td>Same as Base.</td> </tr> <tr> <td>Modified Vulnerable System Confidentiality</td> <td>None</td> <td>No sensitive information contained within the PLC.</td> </tr> <tr> <td>Modified Vulnerable System Integrity</td> <td>High</td> <td>The attacker could modify the operation of the elevator.</td> </tr> <tr> <td>Modified Vulnerable System Availability</td> <td>Low</td> <td>Loss of an elevator compensated by other facility features.</td> </tr> <tr> <td>Modified Subsequent System Confidentiality</td> <td>None</td> <td>No sensitive information contained within the elevator device.</td> </tr> <tr> <td>Modified Subsequent System Integrity</td> <td>High</td> <td>The attacker could modify the operation of the elevator.</td> </tr> <tr> <td>Modified Subsequent System Availability</td> <td>Low</td> <td>Loss of an elevator compensated by other facility features.</td> </tr> <tr> <td>Confidentiality Requirements</td> <td>Low</td> <td>The system contains no secrets and the requirement is reduced.</td> </tr> <tr> <td>Integrity Requirements</td> <td>High</td> <td>There could be a high risk of injury during malfunction to operations.</td> </tr> <tr> <td>Availability Requirements</td> <td>Low</td> <td>Facility redundancy of other elevators reduces the availability requirements.</td> </tr> </tbody> </table> <p><strong>Variation 2: Oil Field Facility Operational Technology</strong></p> <p>In this variation of the vulnerability, the vulnerable device manages a facility such as an oil field. The following metric score variation demonstrates the possible impacts of an exploit against such a deployment.</p> <table> <thead> <tr> <th><strong>B+E v4.0</strong></th> </tr> </thead> <tbody> <tr> <td>7.4</td> </tr> <tr> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:L/IR:H/AR:H/MAV:A/MAC:H/MAT:N/MPR:L/MUI:N/MVC:L/MVI:H/MVA:H/MSC:L/MSI:S/MSA:S">CVSS:4.</a><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:L/IR:H/AR:H/MAV:A/MAC:H/MAT:N/MPR:L/MUI:N/MVC:L/MVI:H/MVA:H/MSC:L/MSI:S/MSA:S">0</a><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:L/IR:H/AR:H/MAV:A/MAC:H/MAT:N/MPR:L/MUI:N/MVC:L/MVI:H/MVA:H/MSC:L/MSI:S/MSA:S">/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/MAV:A/MAC:H/MAT:N/MPR:L/MUI:N/MVC:L/MVI:H/MVA:H/MSC:L/MSI:S/MSA:S/CR:L/IR:H/AR:H/E:P</a></td> </tr> </tbody> </table> <p><strong>Variation 1: CVSS v4 Score: B+E 7.4</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>The attacker can execute the exploit with no specific difficulty. No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>The attacker must require privileges sufficient to access the device.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>The attacker could impact the confidentiality of connected OT devices.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>The attacker could impact the integrity of connected OT devices.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>The attacker could impact the availability of connected OT devices.</td> </tr> <tr> <td>Modified Attack Vector</td> <td>Adjacent</td> <td>The system is disconnected from the Internet. However there is a possibility for lateral control from nearby management systems.</td> </tr> <tr> <td>Modified Attack Complexity</td> <td>High</td> <td>There are FW and Data Diodes that prevent access to the PLC.</td> </tr> <tr> <td>Modified Attack Requirements</td> <td>None</td> <td>Same as Base.</td> </tr> <tr> <td>Modified Privileges Required</td> <td>Low</td> <td>Same as Base.</td> </tr> <tr> <td>Modified User Interaction</td> <td>None</td> <td>Same as Base.</td> </tr> <tr> <td>Modified Vulnerable System Confidentiality</td> <td>Low</td> <td>The attacker could recover some information regarding facility data.</td> </tr> <tr> <td>Modified Vulnerable System Integrity</td> <td>High</td> <td>The attacker could modify the operation of the facility.</td> </tr> <tr> <td>Modified Vulnerable System Availability</td> <td>High</td> <td>The attacker could impact the availability of the PLC.</td> </tr> <tr> <td>Modified Subsequent System Confidentiality</td> <td>Low</td> <td>The attacker could recover information regarding production facility data.</td> </tr> <tr> <td>Modified Subsequent System Integrity</td> <td>Safety</td> <td>The attacker could modify the facility operations, possibly impacting the safety of facility personnel.</td> </tr> <tr> <td>Modified Subsequent System Availability</td> <td>Safety</td> <td>The attacker could impact facility availability, possibly impacting the safety of facility personnel.</td> </tr> <tr> <td>Confidentiality Requirements</td> <td>High</td> <td>The device and facility may hold trade secrets.</td> </tr> <tr> <td>Integrity Requirements</td> <td>High</td> <td>Improper operation of the facility could impact the safety of nearby personnel.</td> </tr> <tr> <td>Availability Requirements</td> <td>High</td> <td>Equipment failure could result in facility downtime.</td> </tr> </tbody> </table> <p><strong>Variation 3: Assembly Line Robots Operational Technology</strong></p> <p>In this variation of the vulnerability, the vulnerable device manages robotic devices in an assembly line. The following metric score variation demonstrates the possible impacts of an exploit against such a deployment.</p> <table> <thead> <tr> <th><strong>B+E v4.0</strong></th> </tr> </thead> <tbody> <tr> <td>8.7</td> </tr> <tr> <td><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/MAV:N/MAC:H/MAT:N/MPR:L/MUI:N/MVC:H/MVI:H/MVA:H/MSC:H/MSI:S/MSA:H/CR:M/IR:H/AR:M/E:P">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/MAV:N/MAC:H/MAT:N/MPR:L/MUI:N/MVC:H/MVI:H/MVA:H/MSC:H/MSI:S/MSA:H/CR:M/IR:H/AR:M/E:P</a></td> </tr> </tbody> </table> <p><strong>Variation 3: CVSS v4 Score: B+E 8.7</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>The attacker can execute the exploit with no specific difficulty. No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>The attacker must require privileges sufficient to access the device.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>Exploitation of the vulnerability results in complete control of the vulnerable system.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>The attacker could impact the confidentiality of connected OT devices.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>High</td> <td>The attacker could impact the integrity of connected OT devices.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>The attacker could impact the availability of connected OT devices.</td> </tr> <tr> <td>Modified Attack Vector</td> <td>Network</td> <td>The system is connected to the Internet for maintenance and services by the robot's suppliers.</td> </tr> <tr> <td>Modified Attack Complexity</td> <td>High</td> <td>There are FW and Data Diodes that prevent access to the PLC.</td> </tr> <tr> <td>Modified Attack Requirements</td> <td>None</td> <td>Same as Base.</td> </tr> <tr> <td>Modified Privileges Required</td> <td>Low</td> <td>Same as Base.</td> </tr> <tr> <td>Modified User Interaction</td> <td>None</td> <td>Same as Base.</td> </tr> <tr> <td>Modified Vulnerable System Confidentiality</td> <td>High</td> <td>The attacker could recover highly valuable information regarding production line data.</td> </tr> <tr> <td>Modified Vulnerable System Integrity</td> <td>High</td> <td>The attacker could modify the operation of the PLC.</td> </tr> <tr> <td>Modified Vulnerable System Availability</td> <td>High</td> <td>The attacker could cause the PLC to stop responding.</td> </tr> <tr> <td>Modified Subsequent System Confidentiality</td> <td>High</td> <td>Potential loss of production data from the connected robotic device.</td> </tr> <tr> <td>Modified Subsequent System Integrity</td> <td>Safety</td> <td>Improper operation of robotic devices could impact the safety of nearby personnel.</td> </tr> <tr> <td>Modified Subsequent System Availability</td> <td>High</td> <td>Equipment failure could result in line downtime.</td> </tr> <tr> <td>Confidentiality Requirements</td> <td>Medium</td> <td>The line contains valuable information.</td> </tr> <tr> <td>Integrity Requirements</td> <td>High</td> <td>Impact to functionality could risk damage to facility and personnel.</td> </tr> <tr> <td>Availability Requirements</td> <td>Medium</td> <td>Although the line should be operational at all times, there is no risk to operators in event of loss of availability.</td> </tr> </tbody> </table> <h2 id="IOT---Healthcare-CVE-2020-10627">IOT - Healthcare (CVE-2020-10627)</h2> <p>Description:</p> <p>Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with access to one of the affected insulin pump models may be able to modify and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.</p> <table> <thead> <tr> <th></th> <th><strong>v3.1</strong></th> <th><strong>v4.0</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Base</strong></td> <td>8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</td> <td>8.6 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/S:P">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/S:P</a></td> </tr> <tr> <td><strong>Base + Environmental</strong></td> <td></td> <td>9.7 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/MSI:S/S:P">CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/MSI:S/S:P</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base + Environmental 9.7</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Adjacent</td> <td>An attacker must be within the local proximity of the device.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>High</td> <td>An attacker could exploit the vulnerability to intercept critical data.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>High</td> <td>An attacker could exploit the vulnerability to change pump settings and control insulin delivery.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Exploit Maturity</td> <td>Unreported</td> <td>There is no known proof-of-concept code or malicious exploitation of this vulnerability.</td> </tr> <tr> <td>Modified Subsequent System</td> <td>Safety</td> <td>Because control of insulin delivery can be changed, there is a health and human safety impact.</td> </tr> <tr> <td>Safety</td> <td>Present</td> <td>Impact on health and human safety from a vulnerability in an OT device may meet definition of IEC 61508 consequence category <strong>critical</strong>.</td> </tr> </tbody> </table> <h2 id="Value-Density-CVE-2020-28196">Value Density (CVE-2020-28196)</h2> <p>Description:</p> <p>MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.</p> <table> <thead> <tr> <th></th> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Base</strong></td> <td>7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</td> <td>8.7 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/V:C">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/V:C</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 8.7</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>High</td> <td>An attacker could cause the application to fail and restart, resulting in a denial of service condition.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>None</td> <td>There is no impact to subsequent systems.</td> </tr> <tr> <td>Value Density</td> <td>Concentrated</td> <td>The value of the Kerberos system is highly concentrated due to its functionality in the network environment.</td> </tr> </tbody> </table> <h2 id="Management-System-CVE-2023-20048">Management System (CVE-2023-20048)</h2> <p>Description:</p> <p>A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software.</p> <p>This vulnerability is due to insufficient authorization of configuration commands that are sent through the web service interface. An attacker could exploit this vulnerability by authenticating to the FMC web services interface and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to execute certain configuration commands on the targeted FTD device. To successfully exploit this vulnerability, an attacker would need valid credentials on the FMC Software.</p> <p>Notes:</p> <p>The vulnerable system is the Firepower Management Center. The subsequent systems are devices managed by the FMC, such as FTD devices. Vulnerability impacts are then limited only to systems managed by the FMC. For the resulting CVSS metrics, there are only subsequent system impacts. There are no additional impacts on the vulnerable system.</p> <table> <thead> <tr> <th></th> <th><strong>v3.1</strong></th> <th><strong>v4.0 Base</strong></th> </tr> </thead> <tbody> <tr> <td><strong>Base</strong></td> <td>9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:H</td> <td>6.4 <a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:H">CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:H</a></td> </tr> </tbody> </table> <p><strong>CVSS v4 Score: Base 6.4</strong></p> <table> <thead> <tr> <th><strong>Metric</strong></th> <th><strong>Value</strong></th> <th><strong>Comments</strong></th> </tr> </thead> <tbody> <tr> <td>Attack Vector</td> <td>Network</td> <td>The vulnerable system is accessible from remote networks.</td> </tr> <tr> <td>Attack Complexity</td> <td>Low</td> <td>No specialized conditions or advanced knowledge are required.</td> </tr> <tr> <td>Attack Requirements</td> <td>None</td> <td>No attack requirements are present.</td> </tr> <tr> <td>Privileges Required</td> <td>Low</td> <td>An attacker must have privileges sufficient to log in to the application web-based management interface.</td> </tr> <tr> <td>User Interaction</td> <td>None</td> <td>No user interaction is required for an attacker to successfully exploit the vulnerability.</td> </tr> <tr> <td>Vulnerable System Confidentiality</td> <td>None</td> <td>There is no impact to the vulnerable system confidentiality. An attacker would gain no additional privileges on the vulnerable system as a result of exploitation.</td> </tr> <tr> <td>Vulnerable System Integrity</td> <td>None</td> <td>There is no impact to the vulnerable system integrity. An attacker would gain no additional privileges on the vulnerable system as a result of exploitation.</td> </tr> <tr> <td>Vulnerable System Availability</td> <td>None</td> <td>There is no impact to the vulnerable system availability. An attacker would gain no additional privileges on the vulnerable system as a result of exploitation.</td> </tr> <tr> <td>Subsequent System Confidentiality</td> <td>High</td> <td>An attacker could execute arbitrary commands on the managed devices and gain access to sensitive information.</td> </tr> <tr> <td>Subsequent System Integrity</td> <td>Low</td> <td>An attacker could execute arbitrary commands on the managed devices and change files or modify the configuration.</td> </tr> <tr> <td>Subsequent System Availability</td> <td>High</td> <td>An attacker could execute arbitrary commands on the managed devices and turn off or disable the device.</td> </tr> </tbody> </table> <h1 id="Version-History">Version History</h1> <table> <thead> <tr> <th><strong>Date</strong></th> <th><strong>Ver</strong></th> <th><strong>Description</strong></th> </tr> </thead> <tbody> <tr> <td>2023-08-10</td> <td>v0.1</td> <td>Initial Publication</td> </tr> <tr> <td>2023-09-29</td> <td>v0.2</td> <td>Grammatical editing changes, updated metrics score comments, and corrected metric score mismatches. Updated CVE-2021-44228</td> </tr> <tr> <td>2023-10-30</td> <td>v0.3</td> <td>Added new examples for Value Density (CVE-2020-28196) and Safety (CVE-2023-30560). Additional error corrections</td> </tr> <tr> <td>2023-11-01</td> <td>v1.0</td> <td>Official Release</td> </tr> <tr> <td>2024-02-12</td> <td>v1.1</td> <td>Error corrections in CVE-2020-3549 and CVE-2013-6014. Additional examples for CVE-2022-47379 OT and CVE-2023-20245 ACL bypass.</td> </tr> <tr> <td>2024-07-13</td> <td>v1.2</td> <td>Additional example for subsequent system (CVE-2023-20048) Additional example for SSRF (CVE-2024-1233) Additional example for CSRF (CVE-2023-5602), see accompanying entry in FAQ Additional example, regreSSHion (CVE-2024-6387)</td> </tr> </tbody> </table></div></div><div id="navbar" data-studio="CU52CV1W8g"><div id="c4" data-studio="Yu8FjCC11g"><ul class="navbar"><li><a href="/cvss">Common Vulnerability Scoring System (CVSS-SIG)</a><ul><li><a href="/cvss/calculator/4.0">Calculator</a></li><li><a href="/cvss/v4.0/specification-document">Specification Document</a></li><li><a href="/cvss/v4.0/user-guide">User Guide</a></li><li><a href="/cvss/v4.0/examples">Examples</a></li><li><a href="/cvss/v4.0/faq">Frequently Asked Questions</a></li><li><a href="/cvss/v4-0">CVSS v4.0 Documentation & Resources</a><ul><li><a href="/cvss/calculator/4.0">CVSS v4.0 Calculator</a></li><li><a href="/cvss/v4.0/specification-document">CVSS v4.0 Specification Document</a></li><li><a href="/cvss/v4.0/user-guide">CVSS v4.0 User Guide</a></li><li><a href="/cvss/v4.0/examples">CVSS v4.0 Examples</a></li><li><a href="/cvss/v4.0/faq">CVSS v4.0 FAQ</a></li></ul></li><li><a href="/cvss/v3-1">CVSS v3.1 Archive</a><ul><li><a href="/cvss/calculator/3.1">CVSS v3.1 Calculator</a></li><li><a href="/cvss/v3.1/specification-document">CVSS v3.1 Specification Document</a></li><li><a href="/cvss/v3.1/user-guide">CVSS v3.1 User Guide</a></li><li><a href="/cvss/v3.1/examples">CVSS v3.1 Examples</a></li><li><a href="/cvss/v3.1/use-design">CVSS v3.1 Calculator Use & Design</a></li></ul></li><li><a href="/cvss/v3-0">CVSS v3.0 Archive</a><ul><li><a href="/cvss/calculator/3.0">CVSS v3.0 Calculator</a></li><li><a href="/cvss/v3.0/specification-document">CVSS v3.0 Specification Document</a></li><li><a href="/cvss/v3.0/user-guide">CVSS v3.0 User Guide</a></li><li><a href="/cvss/v3.0/examples">CVSS v3.0 Examples</a></li><li><a href="/cvss/v3.0/use-design">CVSS v3.0 Calculator Use & Design</a></li></ul></li><li><a href="/cvss/v2">CVSS v2 Archive</a><ul><li><a href="/cvss/v2/guide">CVSS v2 Complete Documentation</a></li><li><a href="/cvss/v2/history">CVSS v2 History</a></li><li><a href="/cvss/v2/team">CVSS-SIG team</a></li><li><a href="/cvss/v2/meetings">SIG Meetings</a></li><li><a href="/cvss/v2/faq">Frequently Asked Questions</a></li><li><a href="/cvss/v2/adopters">CVSS Adopters</a></li><li><a href="/cvss/v2/links">CVSS Links</a></li></ul></li><li><a href="/cvss/v1">CVSS v1 Archive</a><ul><li><a href="/cvss/v1/intro">Introduction to CVSS</a></li><li><a href="/cvss/v1/faq">Frequently Asked Questions</a></li><li><a href="/cvss/v1/guide">Complete CVSS v1 Guide</a></li></ul></li><li><a href="/cvss/data-representations">JSON & XML Data Representations</a></li><li><a href="/cvss/training">CVSS On-Line Training Course</a></li><li><a href="/cvss/identity">Identity & logo usage</a></li></ul></li></ul></div></div><div id="sidebar" data-studio="CU52CV1W8g"><div id="c5" data-studio="Yu8FjCC11g" class="h3labels subbox"><div id="toc"></div> <!-- --></div></div><footer><div id="footer" data-studio="CU52CV1W8g"><div id="c2" data-studio="Yu8FjCC11g"><div class="content"> <div class="support"> <div class="kbsearch bottom"> <p><a href="https://support.first.org"><img src="/_/img/icon-portal_support.svg" alt="FIRST Support" title="FIRST Support" /></a> <input class="kb-search" type="search" placeholder="Do you need help?"></p> </div> </div> <div id="socialnetworks"><a href="/about/sdg" title="FIRST Supported Sustainable Development Goals (SDG)" class="icon-sdg"></a><a rel="me" href="https://infosec.exchange/@firstdotorg" target="_blank" title="@FIRSTdotOrg@infosec.exchange" class="icon-mastodon"></a><a href="https://twitter.com/FIRSTdotOrg" target="_blank" title="Twitter @FIRSTdotOrg" class="icon-tw"></a><a href="https://www.linkedin.com/company/firstdotorg" target="_blank" title="FIRST.Org at LinkedIn" class="icon-linkedin"></a><a href="https://www.facebook.com/FIRSTdotorg" target="_blank" title="FIRST.Org at Facebook" class="icon-fb"></a><a href="https://github.com/FIRSTdotorg" target="_blank" title="FIRST.Org at Github" class="icon-github"></a><a href="https://www.youtube.com/c/FIRSTdotorg" target="_blank" title="FIRST.Org at Youtube" class="icon-youtube"></a><a href="/podcasts" title="FIRST.Org Podcasts" class="icon-podcast"></a></div> <p><a href="/copyright">Copyright</a> © 2015—2024 by Forum of Incident Response and Security Teams, Inc. All Rights Reserved.</p> </div> <p><span class="tlp"></span></p></div></div></footer><script nonce="FqaIbcHRjVpjnpPtdaD8Qw" async="async" src="/_/web.js?20241125212614"></script><script nonce="FqaIbcHRjVpjnpPtdaD8Qw" async="async" src="/_/s.js?20241125-212616"></script></body></html>