« Volver al listado

CVE-2019-17276

Estado: ModificadaMedia (5.4)—

OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-17276",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@netapp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "OnCommand System Manager 9.x",
          "versions": [
            {
              "status": "affected",
              "version": "9.3 prior to 9.3P18 and 9.4 prior to 9.4P2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-03-24T18:15:12.293",
  "references": [
    {
      "url": "https://security.netapp.com/advisory/ntap-20200323-0001/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@netapp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20200323-0001/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting vulnerability that could allow an authenticated attacker to inject arbitrary scripts into the SNMP Community Names label field."
    },
    {
      "lang": "es",
      "value": "OnCommand System Manager versiones 9.3 anteriores a  la versión 9.3P18 y versiones 9.4 anteriores a la versión  9.4P2,  son susceptibles a una vulnerabilidad de tipo cross site scripting que podría permitir a un atacante autenticado inyectar scripts arbitrarios en el campo de etiqueta Community Names SNMP."
    }
  ],
  "lastModified": "2026-06-17T02:23:38.747",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_system_manager:9.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D9ACB33-945B-4755-A9C5-F5EC2AFBB2D1"
            },
            {
              "criteria": "cpe:2.3:a:netapp:oncommand_system_manager:9.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "000FE19E-6600-42FA-9A39-F66D429CEA91"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@netapp.com"
}