« Volver al listado

CVE-2019-6525

Estado: ModificadaAlta (8.8)—

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-6525",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "ics-cert@hq.dhs.gov",
      "affectedData": [
        {
          "vendor": "AVEVA",
          "product": "Wonderware System Platform",
          "versions": [
            {
              "status": "affected",
              "version": "2017 Update 2 and prior"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-04-11T21:29:00.953",
  "references": [
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-029-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec135.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "ics-cert@hq.dhs.gov"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-029-03",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec135.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "ics-cert@hq.dhs.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-522"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account."
    },
    {
      "lang": "es",
      "value": "AVEVA Wonderware System Platform 2017 Actualización 2 y anteriores, usan una cuenta de usuario de red ArchestrA para la autenticación de los procesos del sistema y las comunicaciones entre nodos. Un usuario con pocos privilegios podría hacer uso de una API para obtener las credenciales de esta cuenta."
    }
  ],
  "lastModified": "2026-06-17T02:39:11.540",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:aveva:wonderware_system_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1651D70-AA04-41D6-848C-9ED7D21C1740",
              "versionEndExcluding": "2017"
            },
            {
              "criteria": "cpe:2.3:a:aveva:wonderware_system_platform:2017:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2C5EAD5-34DC-4E67-8E99-5DCAA26D4C8D"
            },
            {
              "criteria": "cpe:2.3:a:aveva:wonderware_system_platform:2017:update_1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2216EF9-386A-4749-9963-11ED4BF631E4"
            },
            {
              "criteria": "cpe:2.3:a:aveva:wonderware_system_platform:2017:update_2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32B78A4A-07C8-43FB-8FB3-DA1D0F1C72FC"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "ics-cert@hq.dhs.gov"
}