« Volver al listado

CVE-2024-4893

Estado: AplazadaCrítica (9.8)—

DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-4893",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-4893",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-15T14:28:12.553304Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "DigiWin",
          "product": "EasyFlow .NET",
          "versions": [
            {
              "status": "affected",
              "version": "3.x"
            },
            {
              "status": "affected",
              "version": "5.x"
            },
            {
              "status": "affected",
              "version": "6.1.x"
            },
            {
              "status": "affected",
              "version": "6.6.x",
              "lessThan": "v6.6.15",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:digiwin:easyflow_.net:6.6.x:*:*:*:*:*:*:*"
          ],
          "vendor": "digiwin",
          "product": "easyflow_.net",
          "versions": [
            {
              "status": "affected",
              "version": "6.6.x"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:digiwin:easyflow_.net:3.x:*:*:*:*:*:*:*"
          ],
          "vendor": "digiwin",
          "product": "easyflow_.net",
          "versions": [
            {
              "status": "affected",
              "version": "3.x"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:digiwin:easyflow_.net:5.x:*:*:*:*:*:*:*"
          ],
          "vendor": "digiwin",
          "product": "easyflow_.net",
          "versions": [
            {
              "status": "affected",
              "version": "5.x"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:digiwin:easyflow_.net:6.1.x:*:*:*:*:*:*:*"
          ],
          "vendor": "digiwin",
          "product": "easyflow_.net",
          "versions": [
            {
              "status": "affected",
              "version": "6.1.x"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-15T03:15:14.493",
  "references": [
    {
      "url": "https://www.twcert.org.tw/en/cp-139-7801-67d07-2.html",
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-7800-843f1-1.html",
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/en/cp-139-7801-67d07-2.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-7800-843f1-1.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands."
    },
    {
      "lang": "es",
      "value": "DigiWin EasyFlow .NET carece de validación para ciertos parámetros de entrada, lo que permite a atacantes remotos inyectar comandos SQL arbitrarios. Esta vulnerabilidad permite el acceso no autorizado para leer, modificar y eliminar registros de bases de datos, así como ejecutar comandos del sistema."
    }
  ],
  "lastModified": "2026-06-17T08:03:07.280",
  "sourceIdentifier": "twcert@cert.org.tw"
}