« Volver al listado

CVE-2024-50585

Estado: AplazadaMedia (4.7)—

Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request.

The vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-50585",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-50585",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-11T18:33:09.697608Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "affectedData": [
        {
          "vendor": "Numerix LLC",
          "product": "License Server Administration System",
          "versions": [
            {
              "status": "affected",
              "version": "1.1_596"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-12-11T15:15:14.920",
  "references": [
    {
      "url": "https://r.sec-consult.com/numerix",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Dec/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the \"Numerix License Server Administration System Login\" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request. \n\n\n\nThe vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch."
    },
    {
      "lang": "es",
      "value": "Los usuarios que hagan clic en un enlace malicioso o visiten un sitio web bajo el control de un atacante pueden infectarse con código JavaScript arbitrario que se ejecuta en el contexto de la página \"Inicio de sesión del sistema de administración del servidor de licencias de Numerix\" (nlslogin.jsp). La vulnerabilidad puede activarse mediante el envío de una solicitud HTTP POST especialmente manipulada. El proveedor no respondió durante varios intentos de contactarlo a través de varios canales, por lo que no hay ninguna solución disponible. En caso de que esté utilizando este software, asegúrese de restringir el acceso y controlar los registros. Intente comunicarse con su persona de contacto para este proveedor y solicite un parche."
    }
  ],
  "lastModified": "2026-06-17T08:04:45.340",
  "sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}