« Volver al listado

CVE-2012-1195

Estado: ModificadaAlta (7.5)—

Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-1195",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-02-18T00:55:02.543",
  "references": [
    {
      "url": "http://osvdb.org/79276",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/47666",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/52023",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1026693",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73207",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/79276",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/47666",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/52023",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1026693",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/73207",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de subida de ficheros sin restricción en andesk/managementsuite/core/core.anonymous/ServerSetup.asmx en el servicio web ServerSetup en Lenovo ThinkManagement Console v9.0.3 permite a atacantes remotos ejecutar código de su elección mediante la subida de archivos con extensión ejecutable a través de un comando PutUpdateFileCore en una petición RunAMTCommand SOAP, y accediendo al archivo a través de una peticición directa al archivo en la raíz web."
    }
  ],
  "lastModified": "2026-06-16T23:39:14.060",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:landesk:lenovo_thinkmanagement_console:9.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EED6B765-A287-493E-85ED-7CC698A6DC0E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "LANDesk is aware of and has resolved this issue. For tracking purposes within LANDesk this vulnerability was given defect number 30319. This issue was resolved in the LD90-SP3-CP_BASE-2012-0412 component patch, available here: http://community.landesk.com/downloads/patch/component/LD90-SP3-CP_BASE-2012-0412a.exe . For details around other fixes contained in the component patch please refer to http://community.landesk.com/support/docs/DOC-24787",
      "lastModified": "2012-05-08T00:00:00",
      "organization": "LANDESK"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}