« Volver al listado

CVE-2022-46383

Estado: ModificadaCrítica (9.8)—

RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has exposed a privileged token via a public API endpoint (Incorrect Access Control). The token can be used to escalate privileges within the Digital Rebar system and grant full administrative access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-46383",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-46383",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-23T16:13:10.589552Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-12-06T15:15:15.967",
  "references": [
    {
      "url": "https://docs.rackn.io/en/latest/doc/security/cve_2022_46383.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://rackn.com/products/rebar/",
      "tags": [
        "Product",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.rackn.io/en/latest/doc/security/cve_2022_46383.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://rackn.com/products/rebar/",
      "tags": [
        "Product",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has exposed a privileged token via a public API endpoint (Incorrect Access Control). The token can be used to escalate privileges within the Digital Rebar system and grant full administrative access."
    },
    {
      "lang": "es",
      "value": "RackN Digital Rebar hasta 4.6.14, 4.7 hasta 4.7.22, 4.8 hasta 4.8.5, 4.9 hasta 4.9.12 y 4.10 hasta 4.10.8 ha expuesto un token privilegiado a través de un endpoint API público (control de acceso incorrecto). El token se puede utilizar para escalar privilegios dentro del sistema Digital Rebar y otorgar acceso administrativo completo."
    }
  ],
  "lastModified": "2026-06-17T05:11:39.977",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rackn:digital_rebar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38C8E8E4-2D51-42EF-A948-1AF6CE7D212A",
              "versionEndIncluding": "4.6.14"
            },
            {
              "criteria": "cpe:2.3:a:rackn:digital_rebar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05A73545-E0D5-4071-B09A-DBD5B37228E5",
              "versionEndIncluding": "4.7.22",
              "versionStartIncluding": "4.7"
            },
            {
              "criteria": "cpe:2.3:a:rackn:digital_rebar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93D773DA-CD98-4C60-A416-0C604785C509",
              "versionEndIncluding": "4.8.5",
              "versionStartIncluding": "4.8"
            },
            {
              "criteria": "cpe:2.3:a:rackn:digital_rebar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F1B5E66-535C-489E-9549-7ED84E1F913B",
              "versionEndIncluding": "4.9.12",
              "versionStartIncluding": "4.9"
            },
            {
              "criteria": "cpe:2.3:a:rackn:digital_rebar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03441E81-8A51-4813-B46C-E43B2C60764D",
              "versionEndIncluding": "4.10.8",
              "versionStartIncluding": "4.10"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}