CVE-2013-6838
Estado: ModificadaAlta (10)—
An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers' installations, which allows remote attackers to gain privileges by leveraging knowledge of this key.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.82%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-6838",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-01-28T00:55:03.847",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2014/Jan/103",
"source": "cve@mitre.org"
},
{
"url": "https://xpd.se/advisories/XPD-2013-001.txt",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2014/Jan/103",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://xpd.se/advisories/XPD-2013-001.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An unspecified Enghouse Interactive Professional Services \"addon product\" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers' installations, which allows remote attackers to gain privileges by leveraging knowledge of this key."
},
{
"lang": "es",
"value": "Un complemento de producto Enghouse Interactive Professional Services sin especificar en Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), cuando se usa OpenVZ y la personalización de reserva, utiliza la misma llave SSH privada a través de distintas instalaciones de consumidores, lo que permite a atacantes remotos obtener privilegios mediante el conocimiento de esta llave."
}
],
"lastModified": "2026-06-17T00:01:01.500",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:enghouseinteractive:ivr_pro:9.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B332A331-167E-458C-BD25-80EB97C6960D"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:openvz:vzkernel:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E0E00996-30AD-4928-81FB-B8088D4D2E54"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}