CVE-2019-20925
Estado: ModificadaAlta (7.5)—
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.68%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-839
- CWE-697
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-20925",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cna@mongodb.com",
"affectedData": [
{
"vendor": "MongoDB Inc.",
"product": "MongoDB Server",
"versions": [
{
"status": "affected",
"version": "4.2",
"lessThan": "4.2.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.0",
"lessThan": "4.0.13",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.6",
"lessThan": "3.6.15",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.4",
"lessThan": "3.4.24",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2020-11-24T11:15:10.607",
"references": [
{
"url": "https://jira.mongodb.org/browse/SERVER-43751",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "cna@mongodb.com"
},
{
"url": "https://jira.mongodb.org/browse/SERVER-43751",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"description": [
{
"lang": "en",
"value": "CWE-839"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-697"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24."
},
{
"lang": "es",
"value": "Un cliente no autenticado puede desencadenar una denegación de servicio al emitir mensajes de protocolo de cable especialmente diseñados, lo que causa a un descompresor de mensajes asignar memoria de manera incorrecta. Este problema afecta a: MongoDB Server de MongoDB Inc versiones v4.2 anteriores a 4.2.1; versiones v4.0 anteriores a 4.0.13; versiones v3.6 anteriores a 3.6.15; versiones v3.4 anteriores a 3.4.24"
}
],
"lastModified": "2026-06-17T02:31:27.030",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB29E1D7-7E63-4038-9F3E-4787B8BE0761",
"versionEndExcluding": "3.4.24",
"versionStartIncluding": "3.4.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "295BD300-FE65-4A87-A3E6-2B7CA845FD52",
"versionEndExcluding": "3.6.15",
"versionStartIncluding": "3.6.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D6052EEF-CD59-4E96-9C8F-054245771F62",
"versionEndExcluding": "4.0.13",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "92555477-B2C9-486C-8583-42C407047811",
"versionEndExcluding": "4.2.1",
"versionStartIncluding": "4.2.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@mongodb.com"
}