CVE-2023-6078
Estado: ModificadaCrítica (9.8)—
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.64%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-6078",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-6078",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-02-21T19:35:34.633796Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "3DS.Information-Security@3ds.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "3DS.Information-Security@3ds.com",
"affectedData": [
{
"vendor": "Dassault Systèmes",
"product": "BIOVIA Materials Studio products",
"versions": [
{
"status": "affected",
"version": "BIOVIA 2021 Golden"
},
{
"status": "affected",
"version": "BIOVIA 2022 Golden"
},
{
"status": "affected",
"version": "BIOVIA 2023 Golden"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-02-01T14:15:55.810",
"references": [
{
"url": "https://www.3ds.com/vulnerability/advisories",
"tags": [
"Vendor Advisory"
],
"source": "3DS.Information-Security@3ds.com"
},
{
"url": "https://www.3ds.com/vulnerability/advisories",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "3DS.Information-Security@3ds.com",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de inyección de comandos del sistema operativo en los productos BIOVIA Materials Studio desde la versión BIOVIA 2021 hasta la versión BIOVIA 2023. La carga de un script perl especialmente manipulado puede provocar la ejecución de comandos arbitrarios."
}
],
"lastModified": "2026-06-17T06:50:00.057",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:3ds:biovia_materials_studio:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE86B786-867B-46D5-9FE0-40FF6ADFE1EF",
"versionEndIncluding": "2023",
"versionStartIncluding": "2021"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "3DS.Information-Security@3ds.com"
}