« Volver al listado

CVE-2022-32272

Estado: ModificadaCrítica (9.8)—

OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-32272",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-06-09T15:15:09.807",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/171549/OPSWAT-Metadefender-Core-4.21.1-Privilege-Escalation.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.opswat.com/mdcore/release-notes",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.opswat.com/mdemail/release-notes",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.opswat.com/mdemail/release-notes/version-5-6-1",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.opswat.com/mdicap/release-notes",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.opswat.com/mdicap/release-notes/version-4-12-1",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://opswat.com",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/171549/OPSWAT-Metadefender-Core-4.21.1-Privilege-Escalation.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.opswat.com/mdcore/release-notes",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.opswat.com/mdemail/release-notes",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.opswat.com/mdemail/release-notes/version-5-6-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.opswat.com/mdicap/release-notes",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.opswat.com/mdicap/release-notes/version-4-12-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://opswat.com",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation."
    },
    {
      "lang": "es",
      "value": "OPSWAT MetaDefender Core antes de la versión 5.1.2, MetaDefender ICAP antes de la versión 4.12.1 y MetaDefender Email Gateway Security antes de la versión 5.6.1 tienen un control de acceso incorrecto, lo que provoca una escalada de privilegios"
    }
  ],
  "lastModified": "2026-06-17T04:47:02.190",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:opswat:metadefender:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B160AB4F-6543-4BD5-9205-570D6666CC0B",
              "versionEndExcluding": "5.1.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}