CVE-2018-12237
Estado: ModificadaAlta (7.2)—
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.2
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.74%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-78
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-12237",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "secure@symantec.com",
"affectedData": [
{
"vendor": "Symantec Corporation",
"product": "Symantec Reporter",
"versions": [
{
"status": "affected",
"version": "10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8"
}
]
}
]
}
],
"published": "2019-01-24T21:29:00.243",
"references": [
{
"url": "http://www.securityfocus.com/bid/106518",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "secure@symantec.com"
},
{
"url": "https://support.symantec.com/en_US/article.SYMSA1465.html",
"tags": [
"Vendor Advisory"
],
"source": "secure@symantec.com"
},
{
"url": "http://www.securityfocus.com/bid/106518",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://support.symantec.com/en_US/article.SYMSA1465.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access can execute arbitrary OS commands with elevated system privileges."
},
{
"lang": "es",
"value": "Symantec Reporter CLI, en sus versiones 10.1 anteriores a la 10.1.5.6 anteriores a la 10.2.1.8, es susceptible a una vulnerabilidad de inyección de comandos del sistema operativo. Un administrador malicioso autenticado con acceso de \"Enable mode\" puede ejecutar comandos arbitrarios del sistema operativo con privilegios de sistema elevados."
}
],
"lastModified": "2026-06-17T01:37:24.150",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:symantec:reporter:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0C80622-75A5-4C97-8C93-B4A09561A948",
"versionEndExcluding": "10.1.5.6",
"versionStartIncluding": "10.1"
},
{
"criteria": "cpe:2.3:a:symantec:reporter:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "531BBC67-9AB6-466D-8D57-7D06816A2E35",
"versionEndExcluding": "10.2.1.8",
"versionStartIncluding": "10.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@symantec.com"
}