« Volver al listado

CVE-2013-6838

Estado: ModificadaAlta (10)—

An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers' installations, which allows remote attackers to gain privileges by leveraging knowledge of this key.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-6838",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-01-28T00:55:03.847",
  "references": [
    {
      "url": "http://seclists.org/fulldisclosure/2014/Jan/103",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://xpd.se/advisories/XPD-2013-001.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2014/Jan/103",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://xpd.se/advisories/XPD-2013-001.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unspecified Enghouse Interactive Professional Services \"addon product\" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers' installations, which allows remote attackers to gain privileges by leveraging knowledge of this key."
    },
    {
      "lang": "es",
      "value": "Un complemento de producto Enghouse Interactive Professional Services sin especificar en Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), cuando se usa OpenVZ y la personalización de reserva, utiliza la misma llave SSH privada a través de distintas instalaciones de consumidores, lo que permite a atacantes remotos obtener privilegios mediante el conocimiento de esta llave."
    }
  ],
  "lastModified": "2026-06-17T00:01:01.500",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:enghouseinteractive:ivr_pro:9.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B332A331-167E-458C-BD25-80EB97C6960D"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:openvz:vzkernel:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E0E00996-30AD-4928-81FB-B8088D4D2E54"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}