« Volver al listado

CVE-2019-18374

Estado: ModificadaCrítica (9.8)—

Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-18374",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secure@symantec.com",
      "affectedData": [
        {
          "vendor": "Symantec",
          "product": "Critical System Protection (CSP)",
          "versions": [
            {
              "status": "affected",
              "version": "8.0"
            },
            {
              "status": "affected",
              "version": "8.0 HF1"
            },
            {
              "status": "affected",
              "version": "8.0 MP1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-11-25T17:15:11.823",
  "references": [
    {
      "url": "https://support.symantec.com/us/en/article.SYMSA1498.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@symantec.com"
    },
    {
      "url": "https://support.symantec.com/us/en/article.SYMSA1498.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing authentication controls."
    },
    {
      "lang": "es",
      "value": "Symantec Critical System Protection (CSP), versiones 8.0, 8.0 HF1 y 8.0 MP1, pueden ser susceptibles a una vulnerabilidad de omisión de autenticación, que es un tipo de problema que puede potencialmente permitir a un actor de amenazas omitir los controles de autenticación existentes."
    }
  ],
  "lastModified": "2026-06-17T02:24:55.890",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_critical_system_protection:8.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EDDDFAE-C77B-4155-9D67-EFE5B0969184"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_critical_system_protection:8.0.0:hotfix1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B05D54C6-88FE-48EE-A1CA-15382DAAE449"
            },
            {
              "criteria": "cpe:2.3:a:broadcom:symantec_critical_system_protection:8.0.0:mp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F67CF1FA-173C-438F-81D1-1DF6A47962C7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@symantec.com"
}