« Volver al listado

CVE-2019-13657

Estado: ModificadaAlta (8.8)—

CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-13657",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vuln@ca.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@ca.com",
      "affectedData": [
        {
          "vendor": "CA Technologies, A Broadcom Company",
          "product": "CA Performance Management",
          "versions": [
            {
              "status": "affected",
              "version": "3.5.x"
            },
            {
              "status": "affected",
              "version": "3.6.x before 3.6.9"
            },
            {
              "status": "affected",
              "version": "3.7.x before 3.7.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-10-17T19:15:10.547",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitary-Command-Execution.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitrary-Command-Execution.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2019/Oct/37",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "https://seclists.org/bugtraq/2019/Oct/26",
      "tags": [
        "Issue Tracking",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "https://techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/ca-20191015-01-security-notice-for-ca-performance-management.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vuln@ca.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitary-Command-Execution.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/154904/CA-Performance-Management-Arbitrary-Command-Execution.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2019/Oct/37",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://seclists.org/bugtraq/2019/Oct/26",
      "tags": [
        "Issue Tracking",
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://techdocs.broadcom.com/us/product-content/recommended-reading/security-notices/ca-20191015-01-security-notice-for-ca-performance-management.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vuln@ca.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security."
    },
    {
      "lang": "es",
      "value": "CA Performance Management versiones 3.5.x, versiones 3.6.x anteriores a 3.6.9 y versiones 3.7.x anteriores a 3.7.4, presenta una vulnerabilidad de credencial predeterminada que puede permitir a un atacante remoto ejecutar comandos arbitrarios y comprometer la seguridad del sistema."
    }
  ],
  "lastModified": "2026-06-17T02:17:10.030",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:ca_performance_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "555A2392-E768-46F0-BE49-CF005161CDEE",
              "versionEndExcluding": "3.6.9",
              "versionStartIncluding": "3.6.0"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:ca_performance_management:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBC72C6D-3EFA-4DBF-A3C9-901920D600F7",
              "versionEndExcluding": "3.7.4",
              "versionStartIncluding": "3.7.0"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:ca_performance_management:3.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24815510-52EB-4759-9E70-AEED9D82E662"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:network_operations:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A49DF530-1EF0-4F48-81FE-63AA669518A8",
              "versionEndIncluding": "19.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vuln@ca.com"
}