« Volver al listado

CVE-2022-1911

Estado: ModificadaMedia (5.3)—

Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-1911",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-1911",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-28T18:14:44.383120Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@m-files.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@m-files.com",
      "affectedData": [
        {
          "vendor": "M-Files",
          "product": "M-Files Server",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "22.6.11534.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "22.6.11505.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2022-11-30T15:15:10.463",
  "references": [
    {
      "url": "https://empower.m-files.com/security-advisories/CVE-2022-1911",
      "source": "security@m-files.com"
    },
    {
      "url": "https://product.m-files.com/security-advisories/cve-2022-1911/",
      "source": "security@m-files.com"
    },
    {
      "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2022-1911/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@m-files.com"
    },
    {
      "url": "https://www.m-files.com/about/trust-center/security-advisories/cve-2022-1911/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@m-files.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-668"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system."
    },
    {
      "lang": "es",
      "value": "Un error en la función del analizador en las versiones de M-Files Server anteriores a 22.6.11534.1 y anteriores a 22.6.11505.0 permitía el acceso no autenticado a cierta información del sistema operativo subyacente."
    }
  ],
  "lastModified": "2026-06-17T04:23:20.597",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:m-files:m-files_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB470E6D-69EF-47E6-AAB5-101AD68CC701",
              "versionEndExcluding": "22.6.11534.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@m-files.com"
}