« Volver al listado

CVE-2022-26507

Estado: ModificadaCrítica (9.8)—

A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-26507",
  "cveTags": [
    {
      "tags": [
        "unsupported-when-assigned"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-14T13:15:11.637",
  "references": [
    {
      "url": "https://Claroty.com",
      "tags": [
        "Not Applicable",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-02",
      "tags": [
        "Mitigation",
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://Claroty.com",
      "tags": [
        "Not Applicable",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-222-02",
      "tags": [
        "Mitigation",
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or CVE-2021-21830. NOTE: This vulnerability only affects products that are no longer supported by the maintainer"
    },
    {
      "lang": "es",
      "value": "** NO SOPORTADO CUANDO SE ASIGNÓ ** Se presenta un desbordamiento de búfer en la región heap de la memoria en XML Decompression DecodeTreeBlock en AT&T Labs Xmill versión 0.7. Un archivo de entrada diseñado puede conllevar a una ejecución de código remota. Esto no es lo mismo que cualquiera de: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, o CVE-2021-21830. NOTA: Esta vulnerabilidad sólo afecta a productos que ya no son soportados por el mantenedor"
    }
  ],
  "lastModified": "2026-06-17T04:35:19.243",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:att:xmill:0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CC987F6-AAFA-4CDE-842D-EA7858A3E7F4"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8DCC0C29-32C2-4463-B98F-AB4B56FF5314",
              "versionEndExcluding": "15.1"
            },
            {
              "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78F6B1CC-488B-48E8-B96B-77A1894E9E92"
            },
            {
              "criteria": "cpe:2.3:a:schneider-electric:ecostruxure_process_expert:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FAB4A9EC-96A2-424D-A858-162E662EBEFB",
              "versionEndExcluding": "2021"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:schneider-electric:remoteconnect:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FFDF36B-30A5-4B35-956C-60DC15CE7EE4"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:schneider-electric:scadapack_470:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F51A7887-4F1A-428C-9E68-260E7262A678"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:scadapack_474:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "58BACC54-6609-4DCE-AEEC-A9C2396635A0"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:scadapack_570:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FFDF44F3-2514-4CB0-A1A4-87123225B0F1"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:scadapack_574:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4F5CDC99-C4C8-43FE-8EA7-65C7EDFD9BA3"
            },
            {
              "criteria": "cpe:2.3:h:schneider-electric:scadapack_575:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DE4172DF-94E3-4AEE-8D6B-9F48DC453B9E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}