CVE-2013-6492
Estado: ModificadaMedia (5.8)—💥 Exploit
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.
CVSS
- Versión: 2.0
- Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 5.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.00%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · RedHat Piranha - Remote Security Bypass (11/12/2013)
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://bugs.centos.org/view.php?id=6825
- http://rhn.redhat.com/errata/RHSA-2014-0174.html
- http://rhn.redhat.com/errata/RHSA-2014-0175.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1043040
- http://bugs.centos.org/view.php?id=6825
- http://rhn.redhat.com/errata/RHSA-2014-0174.html
- http://rhn.redhat.com/errata/RHSA-2014-0175.html
- https://bugzilla.redhat.com/show_bug.cgi?id=1043040
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-6492",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5.8,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-02-14T15:55:05.313",
"references": [
{
"url": "http://bugs.centos.org/view.php?id=6825",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0174.html",
"source": "secalert@redhat.com"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0175.html",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1043040",
"source": "secalert@redhat.com"
},
{
"url": "http://bugs.centos.org/view.php?id=6825",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0174.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://rhn.redhat.com/errata/RHSA-2014-0175.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1043040",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request."
},
{
"lang": "es",
"value": "Piranha Configuration Tool en Piranha 0.8.6 no restringe debidamente el acceso a páginas web, lo que permite a atacantes remotos evadir la autenticación y leer o modificar la configuración LVS a través de una solicitud HTTP POST."
}
],
"lastModified": "2026-06-17T00:00:35.427",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ryan_ohara:piranha:0.8.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32200CEC-F9DB-4856-BBF7-9F43F811E2C7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}