« Volver al listado

CVE-2009-3578

Estado: ModificadaAlta (9.3)—

Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-3578",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-11-24T17:30:00.360",
  "references": [
    {
      "url": "http://securitytracker.com/id?1023228",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.coresecurity.com/content/maya-arbitrary-command-execution",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/508013/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/36636",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1023228",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.coresecurity.com/content/maya-arbitrary-command-execution",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/508013/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/36636",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to \"Script Nodes.\""
    },
    {
      "lang": "es",
      "value": "Autodesk Maya v8.0, v8.5, v2008, v2009, y v2010 y Alias Wavefront Maya v6.5 y v7.0 permite a atacantes remotos ejecutar código de su elección a través de archvio (1) .ma o (2) .mb que usa comando python de Maya Embedded Language (MEL)  u otros comandos MEL no especificados, relacionado con (Script Nodes). \r\n"
    }
  ],
  "lastModified": "2026-06-16T23:11:56.333",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:autodesk:alias_wavefront_maya:6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20859414-D768-4094-AF5F-D9A291FC64A3"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:alias_wavefront_maya:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2AFDD10-A460-444A-9976-7D273624D21A"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:autodesk_maya:8.0:2008:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07199D2C-17B7-4E7A-AD4A-5D0FBE4642C6"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:autodesk_maya:8.0:2009:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC5F2645-4D92-412C-841F-00D841433607"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:autodesk_maya:8.0:2010:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA84789E-C639-435C-A6AC-922C4B968A38"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:autodesk_maya:8.5:2008:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CE43DCB-DF17-4B90-ADBC-2DD05C6C3A18"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:autodesk_maya:8.5:2009:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1096BD88-DC22-4228-872A-70300C6A51C9"
            },
            {
              "criteria": "cpe:2.3:a:autodesk:autodesk_maya:8.5:2010:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6FCFED79-D472-4CF4-A240-F549DB3DD600"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}