« Volver al listado

CVE-2022-31619

Estado: ModificadaAlta (8.8)—

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions < V13.1.0.9), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter V14.0 (All versions < V14.0.0.2). Java EE Server Manager HTML Adaptor in Teamcenter consists of default hardcoded credentials. Access to the application allows a user to perform a series of actions that could potentially lead to remote code execution with elevated permissions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-31619",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "Teamcenter V12.4",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V12.4.0.13"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.0",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.0.0.9"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.1",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.1.0.9"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.2",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.2.0.9"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V13.3",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V13.3.0.3"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "Teamcenter V14.0",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V14.0.0.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-14T10:15:20.600",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-220589.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-220589.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-798"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions < V13.1.0.9), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter V14.0 (All versions < V14.0.0.2). Java EE Server Manager HTML Adaptor in Teamcenter consists of default hardcoded credentials. Access to the application allows a user to perform a series of actions that could potentially lead to remote code execution with elevated permissions."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en Teamcenter V12.4 (Todas las versiones anteriores a V12.4.0.13), Teamcenter V13.0 (Todas las versiones anteriores a V13.0.0.9), Teamcenter V13.1 (Todas las versiones anteriores a V13.1.0.9), Teamcenter V13.2 (Todas las versiones anteriores a V13.2.0.9), Teamcenter V13.3 (Todas las versiones anteriores a V13.3.0.3), Teamcenter V14.0 (Todas las versiones anteriores a V14.0.0.2). El adaptador HTML de Java EE Server Manager en Teamcenter consta de credenciales predeterminadas codificadas. El acceso a la aplicación permite a un usuario realizar una serie de acciones que podrían llevar a la ejecución remota de código con permisos elevados"
    }
  ],
  "lastModified": "2026-06-17T04:45:49.013",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA684297-D33B-4E81-A19F-29514EB409A0",
              "versionEndExcluding": "12.4.0.13",
              "versionStartIncluding": "12.4"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0EDF96B-DF5B-4A9E-A70E-FD3EEE8067CD",
              "versionEndExcluding": "13.0.0.9",
              "versionStartIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80958809-7B4E-4B17-8438-1AA0F5960F90",
              "versionEndExcluding": "13.1.0.9",
              "versionStartIncluding": "13.1"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B6BC3EC-D245-410B-8332-3A5434CE75C3",
              "versionEndExcluding": "13.2.0.9",
              "versionStartIncluding": "13.2"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "704B0DB9-516D-4CDE-89AE-D36100B3B84A",
              "versionEndExcluding": "13.3.0.3",
              "versionStartIncluding": "13.3"
            },
            {
              "criteria": "cpe:2.3:a:siemens:teamcenter:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A83E678F-3A9A-4F07-9D03-C224741877C4",
              "versionEndExcluding": "14.0.0.2",
              "versionStartIncluding": "14.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}