« Volver al listado

CVE-2019-10028

Estado: ModificadaAlta (7.5)—

Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-10028",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-report@netflix.com",
      "affectedData": [
        {
          "vendor": "Netflix",
          "product": "Dial Reference Source Code Repo (https://github.com/Netflix/dial-reference)",
          "versions": [
            {
              "status": "affected",
              "version": "Before June 18"
            },
            {
              "status": "affected",
              "version": "2019."
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-06-21T21:15:09.710",
  "references": [
    {
      "url": "https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2019-002.md",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-report@netflix.com"
    },
    {
      "url": "https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2019-002.md",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019."
    },
    {
      "lang": "es",
      "value": "Denegación de servicio (DOS) en el código fuente usado de Dial Reference antes del 18 de junio de 2019."
    }
  ],
  "lastModified": "2026-06-17T02:10:04.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netflix:dial_reference:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA95045C-3C4C-4474-967A-192DA1877309",
              "versionEndExcluding": "6-18-2019"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-report@netflix.com"
}