« Volver al listado

CVE-2022-24951

Estado: ModificadaAlta (7)—

A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket, enabling access to Eternal Terminal clients which attempt to connect in the future.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-24951",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Jason Gauci",
          "product": "Eternal Terminal",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "6.2.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-16T01:15:12.567",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/02/16/1",
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://github.com/MisterTea/EternalTerminal/releases/tag/et-v6.2.0",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-546v-59j5-g95q",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2023/02/16/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/MisterTea/EternalTerminal/releases/tag/et-v6.2.0",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/metaredteam/external-disclosures/security/advisories/GHSA-546v-59j5-g95q",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-assign@fb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Terminal's IPC socket, enabling access to Eternal Terminal clients which attempt to connect in the future."
    },
    {
      "lang": "es",
      "value": "Una condición de carrera se presenta en Eternal Terminal versiones anteriores a 6.2.0, que permite a un atacante local secuestrar el socket IPC de Eternal Terminal, permitiendo el acceso a clientes de Eternal Terminal que intenten conectarse en el futuro."
    }
  ],
  "lastModified": "2026-06-17T04:32:50.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:eternal_terminal_project:eternal_terminal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F81EA524-B9EE-48C8-B8BF-8E53D2AAD574",
              "versionEndExcluding": "6.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}